Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

pypi django Security Advisories

Browse all Security Advisories for pypi django

Loading...
Moderate
GSA_kwCzR0hTQS12bThxLW01N2ctcGZmM84AA6CU
Regular expression denial-of-service in Django
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 26.8
Published: 8 months ago
High
GSA_kwCzR0hTQS14eGo5LWY2cnYtbTN4NM4AA5IP
Django denial-of-service attack in the intcomma template filter
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 29.9
Published: 10 months ago
Moderate
GSA_kwCzR0hTQS03aDRwLTI3bWgtaG1yd84AA25h
Django Denial of service vulnerability in django.utils.encoding.uri_to_iri
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 26.8
Published: about 1 year ago
High
GSA_kwCzR0hTQS1xMmpmLWg5am0tbTdwNM4AAxVW
Django contains Uncontrolled Resource Consumption via cached header
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: almost 2 years ago
High
GSA_kwCzR0hTQS1xcnc1LTVoMjgtNmNtZ84AAvXa
Django denial-of-service vulnerability in internationalized URLs
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: about 2 years ago
Critical
GSA_kwCzR0hTQS03OHZ4LWdnY2gtd2dobc4AAfPg
Django Allows Redirect via Data URL
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: over 2 years ago
High
GSA_kwCzR0hTQS01OXc4LTR3bTItNHh3OM4AAfPe
Django Image Field Vulnerable to Image Decompression Bombs
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
High
GSA_kwCzR0hTQS0yNjU1LXE0NTMtMjJmOc4AAfNa
Django Allows Arbitrary URL Generation
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
High
GSA_kwCzR0hTQS12ampwLTlyODMtMjJyY84AAe3i
Django Directory Traversal via ssi template tag
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 43.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS00Nng0LTlqbXYtamM4cM4AAdCD
Django Access Restrictions Bypass
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 27.8
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS02NTY1LWZnODYtNmpjeM4AAc0O
Django Cross-site Scripting Vulnerability
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS02d2NyLXdjcW0tM21maM4AAcl8
Django settings leak in date template filter
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 14.2
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS03cWZ3LWo3aHAtdjQ1Z84AAcfU
Django WSGI Header Spoofing Vulnerability
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 26.8
Published: over 2 years ago
High
GSA_kwCzR0hTQS1qaGpnLXcyY3AtNWo0NM4AAce9
Django DoS in django.views.static.serve
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS1ndjk4LWc2MjgtbTl4Nc4AAce6
Django Cross-site Scripting Vulnerability
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: over 2 years ago
High
GSA_kwCzR0hTQS04OWhqLXhmeDUtN3E2Ns4AAcJo
Django Reuses Cached CSRF Token
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
High
GSA_kwCzR0hTQS13cWpqLWh4ODQtdjQ0Oc4AAcJQ
Django Vulnerable to MySQL Injection
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS00ODk0LTV2cWMtNnIycs4AAZ0v
Django cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: over 2 years ago
Low
GSA_kwCzR0hTQS1mcDZwLTV4dnctbTc0Zs4AAZQc
Django User Enumeration Vulnerability
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 15.7
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS1wdzI3LXc3dzQtOXFjN84AAZQd
Django XSS Vulnerability
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 37.4
Published: over 2 years ago
High
GSA_kwCzR0hTQS1xNXF3LTQzNjQtNWhobc4AAYwZ
Django Vulnerable to HTTP Response Splitting Attack
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
High
GSA_kwCzR0hTQS1jcmhtLXFwamMtY202NM4AAXr9
Django CSRF Protection Bypass
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
High
GSA_kwCzR0hTQS1ybTJqLXg1OTUtcTljas4AAXiH
Django Vulnerable to Cache Poisoning
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS1jOGM4LTk0NzItdzUyaM4AAV-L
Django Cross-site scripting Vulnerability
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS02MjVnLWd4OGMteGNtZ84AAVE-
Django Middleware Enables Session Hijacking
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 32.9
Published: over 2 years ago
High
GSA_kwCzR0hTQS1mN2NtLWNjZnAtM3E0cs4AAVFA
Django Incorrectly Validates URLs
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
High
GSA_kwCzR0hTQS0yOTZ3LTZxaHEtZ2Y5Ms4AAU-L
Django denial of service via file upload naming
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
High
GSA_kwCzR0hTQS1yNWNqLXd2MjQtOTJwNc285A
Django cross-site request forgery (CSRF) vulnerability
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS01NHFqLTQ4dngtY3I5Zs22-A
Django Cross-site scripting (XSS) vulnerability
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS05NXJ3LWZ4OHItMzZ2Ns0opg
Cross-site Scripting in Django
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: almost 3 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTY4dzgtcWpxMy0yZ2Zt
Path Traversal in Django
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 24.8
Published: over 3 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZyMjgtNTY5ai01M2M0
Django Incorrect Default Permissions
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 3 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ2Z2YtNmg2aC0zMzIy
Django Directory Traversal via archive.extract
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 26.8
Published: over 3 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhtcjQtbTJoNS0zM3F4
SQL injection in Django
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: almost 5 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZmcTYtaHE1ci0yN3I2
Django Potential account hijack via password reset form
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: almost 5 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg1ODItMnBjaC0zeHYz
Django Denial-of-service by filling session store
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 5 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZjM2otYzY0bS1xaGdx
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
Ecosystems: packagist, maven, nuget, npm, pypi, rubygems
Packages: maximebf/debugbar, org.webjars.npm:jquery, jQuery, jquery, django, jquery-rails
Source: GitHub Advisory Database
Blast Radius: 163.1
Published: over 5 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg0aHYtbTRoNC1taHdn
Django open redirect
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: almost 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJmOXgtNXY3NS0zcXY0
Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filters
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 26.8
Published: almost 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVoZzMtNmMyZi1mM3dy
Django open redirect
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJmNGotajI3Mi1majg2
Django vulnerable to information leakage in AuthenticationForm
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZteDMtM3ZxZy1ocHAy
Django allows unprivileged users to read the password hashes of arbitrary accounts
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 24.8
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTd3cGgtZmM0dy13cXAy
Improper date handling in Django
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: over 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ3cjUtcTlyeC0yOTRm
Improper query string handling in Django
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 32.9
Published: over 6 years ago
Statistics
Advisories: 20,668
Packages: 9,040
Repositories: 2
Ecosystems: 12
Filter by Package
tensorflow 433 tensorflow-gpu 427 tensorflow-cpu 423 Django 100 apache-airflow 85 Plone 72 ansible 63 salt 56 apache-superset 51 nova 47 mlflow 46 django 44 rdiffweb 42 plone 41 vyper 38 moin 35 matrix-synapse 35 gradio 34 keystone 31 Pillow 31 opencv-contrib-python 31 opencv-python 31 pillow 26 glance 20 langchain 20 mindsdb 18 cobbler 18 mercurial 18 notebook 17 paddlepaddle 16 pyload-ng 16 neutron 16 PaddlePaddle 16 cryptography 16 ethyca-fides 15 calibreweb 15 OctoPrint 15 aiohttp 14 modoboa 14 lollms 14 pyftpdlib 14 vantage6 13 wagtail 12 roundup 12 urllib3 12 twisted 12 zenml 12 swift 12 waitress 11 trytond 11 horizon 11 onionshare-cli 11 opencv-contrib-python-headless 10 opencv-python-headless 10 Flask-AppBuilder 10 nautobot 10 sentry 10 ryu 9 python-keystoneclient 9 cinder 9 pyspark 9 kiwitcms 9 zope 9 aubio 8 ckan 8 pgadmin4 8 numpy 8 ipython 8 litellm 8 trac 8 label-studio 8 Zope 8 pysaml2 7 lief 7 pip 7 jupyter-server 7 matrix-sydent 7 inventree 7 Products.CMFPlone 7 scrapy 7 ansible-core 6 yt-dlp 6 tuf 6 mage-ai 6 aim 6 tornado 6 requests 6 mailman 6 changedetection.io 6 Zope2 6 apache-airflow-providers-apache-hive 6 graphite-web 6 web2py 6 Moin 6 lxml 6 ait-core 5 oauthenticator 5 nltk 5 dtale 5 saleor 5 omero-web 5 pretix 5 whoogle-search 5 paramiko 5 torchserve 5 langchain-experimental 5 werkzeug 5 bleach 5 lmdb 5 feedparser 5 grpc 5 Werkzeug 5 python-gnupg 5 grpcio 5 jupyterhub 5 Jinja2 5 Pygments 4 Scrapy 4 codechecker 4 indico 4 apache-iotdb 4 software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk 4 aws-iot-device-sdk-v2 4 awsiotsdk 4 esphome 4 nvflare 4 indy-node 4 GitPython 4 onnx 4 reportlab 4 FreeTAKServer-UI 4 transformers 4 jupyterlab 4 bottle 4 apache-submarine 4 barbican 4 markdown2 4 buildbot 4 httpie 4 pywasm3 4 streamlit 4 open-webui 4 Nova 4 mobsf 4 Weblate 4 PyPDF2 4 Keystone 4 dbt-core 4 tripleo-heat-templates 4 langflow 4 Flask-Security-Too 4 keylime 4 qutebrowser 4 langchain-community 4 Radicale 4 jwcrypto 4 wasmtime 4 h2o 3 docassemble.webapp 3 asyncssh 3 rsa 3 jupyter-server-proxy 3 vanna 3 mistune 3 clearml 3 localstack 3 bitlyshortener 3 pyyaml 3 keyring 3 fava 3 quokka 3 httplib2 3 dulwich 3 scikit-learn 3 sosreport 3 AccessControl 3 torch 3 ray 3 gerapy 3 ecdsa 3 wasmtime 3 Twisted 3 ajenti 3 sanic 3 ydata-profiling 3 pandasai 3 wasm3 3 certifi 3 protobuf 3 python-jose 3 octavia 3 io.grpc:grpc-protobuf 3 anki 3 homeassistant 3 mysql-connector-python 3 pycrypto 3 llama-index-core 3 django-helpdesk 3 ansible-runner 3 SQLAlchemy 3