Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Djangoproject

First CVE: Jan 23, 2007Active for: 20 yearsTotal CVEs: 165
51.4
VTI Score
TOP TARGET

Django is a widely adopted web-application framework maintained by the Django Project, whose relatively concentrated product portfolio — including the core framework, Channels for asynchronous support, and related utilities — underpins a large ecosystem of internet-facing applications across the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through application-layer weakness classes including SQL injection, cross-site scripting, improper input validation, path traversal, and resource-exhaustion conditions that reflect the framework's role in handling untrusted web requests and database interaction. A meaningful share of these disclosures acquire public exploit code, making Django advisories operationally urgent for organizations running exposed applications built with the framework. The concentration of exposure in the core framework and Channels means that patching one product can address risk across thousands of downstream applications, making this vendor's release cycle a critical dependency for web-application defenders. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
165
Total CVEs
More Total CVEs than 100% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Djangoproject over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2007
19 years ago
Most Recent CVE
Jul 7, 2026
21 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (165 CVEs).

165 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-34265CRITICAL
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a k
Jul 4, 20229.880NOYES
CVE-2021-35042CRITICAL
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.
Jul 2, 20219.867NOYES
CVE-2020-7471CRITICAL
Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer
Feb 3, 20209.867NONO
CVE-2019-19844CRITICAL
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after cas
Dec 18, 20199.860NOYES
CVE-2025-64459CRITICAL
An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q
Nov 5, 20259.158NOYES
CVE-2023-24580HIGH
An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of p
Feb 15, 20237.557NONO
CVE-2019-14234CRITICAL
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for djang
Aug 9, 20199.857NONO
CVE-2026-1207HIGH
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to in
Feb 3, 20268.354NOYES
CVE-2022-23833HIGH
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infini
Feb 3, 20227.552NONO
CVE-2023-23969HIGH
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a p
Feb 1, 20237.550NONO
View all 165 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products165 CVEs
53%
35%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network111 (67.3%)
Unknown54 (32.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low98 (59.4%)
High13 (7.9%)
Unknown54 (32.7%)
User Interaction
None90 (54.5%)
Unknown54 (32.7%)
Required21 (12.7%)
Privileges Required
Low9 (5.5%)
High4 (2.4%)
None98 (59.4%)
Unknown54 (32.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (165 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
3.6% of CVEs· 95th percentile
ExploitDB
3 CVEs
1.8% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Djangoproject.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Djangoproject — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Djangoproject's Products

View all 7 CNAs →

Top CWEs