Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

pypi django Security Advisories

Browse all Security Advisories for pypi django

Loading...
Moderate
GSA_kwCzR0hTQS12bThxLW01N2ctcGZmM84AA6CU
Regular expression denial-of-service in Django
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 26.8
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS14eGo5LWY2cnYtbTN4NM4AA5IP
Django denial-of-service attack in the intcomma template filter
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 29.9
Published: 9 months ago
Moderate
GSA_kwCzR0hTQS03aDRwLTI3bWgtaG1yd84AA25h
Django Denial of service vulnerability in django.utils.encoding.uri_to_iri
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 26.8
Published: 12 months ago
High
GSA_kwCzR0hTQS1xMmpmLWg5am0tbTdwNM4AAxVW
Django contains Uncontrolled Resource Consumption via cached header
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 1 year ago
High
GSA_kwCzR0hTQS1xcnc1LTVoMjgtNmNtZ84AAvXa
Django denial-of-service vulnerability in internationalized URLs
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS03OHZ4LWdnY2gtd2dobc4AAfPg
Django Allows Redirect via Data URL
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: over 2 years ago
High
GSA_kwCzR0hTQS01OXc4LTR3bTItNHh3OM4AAfPe
Django Image Field Vulnerable to Image Decompression Bombs
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
High
GSA_kwCzR0hTQS0yNjU1LXE0NTMtMjJmOc4AAfNa
Django Allows Arbitrary URL Generation
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
High
GSA_kwCzR0hTQS12ampwLTlyODMtMjJyY84AAe3i
Django Directory Traversal via ssi template tag
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 43.5
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS00Nng0LTlqbXYtamM4cM4AAdCD
Django Access Restrictions Bypass
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 27.8
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS02NTY1LWZnODYtNmpjeM4AAc0O
Django Cross-site Scripting Vulnerability
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS02d2NyLXdjcW0tM21maM4AAcl8
Django settings leak in date template filter
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 14.2
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS03cWZ3LWo3aHAtdjQ1Z84AAcfU
Django WSGI Header Spoofing Vulnerability
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 26.8
Published: over 2 years ago
High
GSA_kwCzR0hTQS1qaGpnLXcyY3AtNWo0NM4AAce9
Django DoS in django.views.static.serve
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS1ndjk4LWc2MjgtbTl4Nc4AAce6
Django Cross-site Scripting Vulnerability
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: over 2 years ago
High
GSA_kwCzR0hTQS13cWpqLWh4ODQtdjQ0Oc4AAcJQ
Django Vulnerable to MySQL Injection
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: over 2 years ago
High
GSA_kwCzR0hTQS04OWhqLXhmeDUtN3E2Ns4AAcJo
Django Reuses Cached CSRF Token
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS00ODk0LTV2cWMtNnIycs4AAZ0v
Django cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: over 2 years ago
Low
GSA_kwCzR0hTQS1mcDZwLTV4dnctbTc0Zs4AAZQc
Django User Enumeration Vulnerability
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 15.7
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS1wdzI3LXc3dzQtOXFjN84AAZQd
Django XSS Vulnerability
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 37.4
Published: over 2 years ago
High
GSA_kwCzR0hTQS1xNXF3LTQzNjQtNWhobc4AAYwZ
Django Vulnerable to HTTP Response Splitting Attack
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
High
GSA_kwCzR0hTQS1jcmhtLXFwamMtY202NM4AAXr9
Django CSRF Protection Bypass
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
High
GSA_kwCzR0hTQS1ybTJqLXg1OTUtcTljas4AAXiH
Django Vulnerable to Cache Poisoning
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS1jOGM4LTk0NzItdzUyaM4AAV-L
Django Cross-site scripting Vulnerability
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS02MjVnLWd4OGMteGNtZ84AAVE-
Django Middleware Enables Session Hijacking
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 32.9
Published: over 2 years ago
High
GSA_kwCzR0hTQS1mN2NtLWNjZnAtM3E0cs4AAVFA
Django Incorrectly Validates URLs
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
High
GSA_kwCzR0hTQS0yOTZ3LTZxaHEtZ2Y5Ms4AAU-L
Django denial of service via file upload naming
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
High
GSA_kwCzR0hTQS1yNWNqLXd2MjQtOTJwNc285A
Django cross-site request forgery (CSRF) vulnerability
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS01NHFqLTQ4dngtY3I5Zs22-A
Django Cross-site scripting (XSS) vulnerability
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS05NXJ3LWZ4OHItMzZ2Ns0opg
Cross-site Scripting in Django
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: over 2 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTY4dzgtcWpxMy0yZ2Zt
Path Traversal in Django
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 24.8
Published: over 3 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZyMjgtNTY5ai01M2M0
Django Incorrect Default Permissions
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 3 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ2Z2YtNmg2aC0zMzIy
Django Directory Traversal via archive.extract
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 26.8
Published: over 3 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhtcjQtbTJoNS0zM3F4
SQL injection in Django
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: over 4 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZmcTYtaHE1ci0yN3I2
Django Potential account hijack via password reset form
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: almost 5 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg1ODItMnBjaC0zeHYz
Django Denial-of-service by filling session store
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 5 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZjM2otYzY0bS1xaGdx
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
Ecosystems: maven, nuget, npm, pypi, rubygems
Packages: org.webjars.npm:jquery, jQuery, jquery, django, jquery-rails
Source: GitHub Advisory Database
Blast Radius: 135.8
Published: over 5 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg0aHYtbTRoNC1taHdn
Django open redirect
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: almost 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJmOXgtNXY3NS0zcXY0
Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filters
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 26.8
Published: almost 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVoZzMtNmMyZi1mM3dy
Django open redirect
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJmNGotajI3Mi1majg2
Django vulnerable to information leakage in AuthenticationForm
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZteDMtM3ZxZy1ocHAy
Django allows unprivileged users to read the password hashes of arbitrary accounts
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 24.8
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTd3cGgtZmM0dy13cXAy
Improper date handling in Django
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ3cjUtcTlyeC0yOTRm
Improper query string handling in Django
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 32.9
Published: over 6 years ago
Statistics
Advisories: 20,359
Packages: 8,934
Repositories: 2
Ecosystems: 12
Filter by Package
tensorflow 433 tensorflow-gpu 425 tensorflow-cpu 422 Django 100 apache-airflow 84 Plone 72 ansible 63 salt 55 apache-superset 51 nova 47 mlflow 46 django 44 rdiffweb 42 plone 41 vyper 38 moin 35 matrix-synapse 35 gradio 32 opencv-python 31 Pillow 31 opencv-contrib-python 31 keystone 31 pillow 26 glance 20 mercurial 18 mindsdb 18 langchain 18 cobbler 17 PaddlePaddle 17 notebook 17 cryptography 16 neutron 16 paddlepaddle 15 ethyca-fides 15 pyload-ng 15 modoboa 14 pyftpdlib 14 lollms 13 twisted 13 vantage6 13 OctoPrint 13 urllib3 12 swift 12 roundup 12 aiohttp 12 wagtail 12 calibreweb 12 zenml 11 onionshare-cli 11 horizon 11 opencv-contrib-python-headless 10 opencv-python-headless 10 sentry 10 trytond 10 Flask-AppBuilder 10 nautobot 10 Zope 9 zope 9 kiwitcms 9 waitress 9 cinder 9 ryu 9 python-keystoneclient 9 aubio 8 litellm 8 numpy 8 label-studio 8 ckan 8 pgadmin4 8 pyspark 8 trac 8 ipython 8 Products.CMFPlone 7 pip 7 lief 7 jupyter-server 7 scrapy 7 pysaml2 7 inventree 7 matrix-sydent 7 graphite-web 6 mailman 6 tornado 6 aim 6 mage-ai 6 requests 6 Zope2 6 lxml 6 web2py 6 yt-dlp 6 tuf 6 apache-airflow-providers-apache-hive 6 Moin 6 Jinja2 5 oauthenticator 5 pretix 5 paramiko 5 whoogle-search 5 saleor 5 feedparser 5 lmdb 5 omero-web 5 torchserve 5 grpcio 5 grpc 5 bleach 5 jupyterhub 5 python-gnupg 5 nltk 5 ait-core 5 dtale 5 langchain-experimental 5 werkzeug 4 GitPython 4 starlette 4 Radicale 4 Keystone 4 Werkzeug 4 tripleo-heat-templates 4 Scrapy 4 dbt-core 4 Nova 4 apache-iotdb 4 nvflare 4 changedetection.io 4 transformers 4 bottle 4 FreeTAKServer-UI 4 jwcrypto 4 buildbot 4 keylime 4 esphome 4 Flask-Security-Too 4 Weblate 4 open-webui 4 mobsf 4 PyPDF2 4 software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk 4 indico 4 aws-iot-device-sdk-v2 4 barbican 4 indy-node 4 streamlit 4 markdown2 4 ansible-core 4 reportlab 4 httpie 4 jupyterlab 4 qutebrowser 4 awsiotsdk 4 apache-submarine 4 Pygments 4 gerapy 3 localstack 3 vanna 3 django-tinymce 3 pandasai 3 ujson 3 apache-libcloud 3 pywasm3 3 Mezzanine 3 homeassistant 3 datasette 3 sickrage 3 dulwich 3 pyyaml 3 anki 3 sosreport 3 rsa 3 fava 3 io.grpc:grpc-protobuf 3 ansible-runner 3 torch 3 flask 3 tinymce 3 Red-DiscordBot 3 pycrypto 3 asyncua 3 asyncssh 3 tinymce/tinymce 3 quokka 3 wger 3 h2o 3 ray 3 llama-index 3 TinyMCE 3 docassemble.webapp 3 slixmpp 3 mistune 3 openvpn-monitor 3 setuptools 3 keyring 3 mayan-edms 3 copyparty 3 scikit-learn 3 plone.supermodel 3 keystonemiddleware 3 ecdsa 3 clearml 3 jupyter-server-proxy 3