pkg:Debian/python-django
219 total CVEsCRITICAL22HIGH88MEDIUM97LOW8
✅ Check your installed version
All known vulnerabilities
- from 0
- from 0, < 3:4.2.17-1
- from 0, < 1:1.11.29-1+deb10u8
- from 0, < 2:2.2.28-1~deb11u2
- CRITICAL9.8CVE-2022-34265Django `Trunc()` and `Extract()` database functions vulnerable to SQL Injectionfrom 0, < 2:2.2.28-1~deb11u1
- from 0, < 1.6.3-1
- from 0, < 1.6.3-1
- from 0, < 1.2.3-3+squeeze10
- from 0, < 1.7.11-1+deb8u2
- from 0, < 1:1.10.3-1
- from 0, < 2:2.2.28-1~deb11u1
- from 0, < 2:2.2.28-1~deb11u1
- from 0, < 1:1.10.7-2+deb9u16
- from 0, < 2:2.2.10-1
- from 0, < 1:1.10.7-2+deb9u8
- from 0, < 2:2.2.9-1
- from 0, < 1.7.11-1+deb8u8
- from 0, < 1:1.10.7-2+deb9u7
- from 0, < 2:2.2.4-1
- CRITICAL9.1CVE-2025-64459Potential SQL injection via _connector keyword argument in QuerySet and Q objectsfrom 0, < 2:2.2.28-1~deb11u10
- CRITICAL9.1CVE-2025-64459Potential SQL injection via _connector keyword argument in QuerySet and Q objectsfrom 0, < 2:2.2.28-1~deb11u10
- from 0, < 2:2.2.28-1~deb11u11
- from 0, < 2:2.2.28-1~deb11u1
- from 0, < 1:1.10.7-2+deb9u17
- from 0, < 2:2.2.11-1
- from 0, < 1.2.3-3+squeeze7
- from 0, < 1.5.3-1
- from 0, < 1.4.22-1+deb7u2
- from 0, < 1:1.10.3-1
- from 0
- HIGH7.5CVE-2026-33034Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypassfrom 0
- HIGH7.5CVE-2026-1285Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methodsfrom 0, < 2:2.2.28-1~deb11u12
- from 0, < 3:3.2.25-0+deb12u2
- from 0, < 2:2.2.28-1~deb11u10
- HIGH7.5CVE-2025-64458Potential denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windowsfrom 0
- from 0, < 2:2.2.28-1~deb11u3
- from 0, < 2:2.2.28-1~deb11u3
- from 0, < 2:2.2.28-1~deb11u11
- from 0, < 2:2.2.28-1~deb11u11
- from 0
- from 0, < 2:2.2.28-1~deb11u2
- from 0, < 1:1.11.29-1+deb10u9
- from 0, < 2:2.2.28-1~deb11u2
- from 0, < 2:2.2.28-1~deb11u2
- from 0, < 1:1.11.29-1+deb10u7
- from 0, < 1:1.11.29-1+deb10u6
- from 0, < 2:2.2.28-1~deb11u2
- from 0, < 2:2.2.28-1~deb11u1
- from 0, < 1.4.1-1
- HIGH7.5CVE-2012-3444Django vulnerable to Improper Restriction of Operations within the Bounds of a Memory Bufferfrom 0, < 1.4.1-1
- from 0, < 1.4.2-1
- from 0, < 1.2.3-3+squeeze5
- from 0, < 1.2.3-3+squeeze8
- from 0, < 1.5.4-1
- from 0, < 1.7.1-1.1
- from 0, < 1.7.1-1.1
- from 0, < 1.7.10-1
- from 0, < 1.6.3-1
- from 0, < 1.7.9-1
- from 0, < 1.2.3-3+squeeze14
- from 0, < 1.7.10-1
- from 0, < 1.4.5-1+deb7u13
- from 0, < 1.4.22-1+deb7u1
- from 0, < 1.7.11-1+deb8u1
- from 0, < 1:1.10-1
- from 0, < 1.3.1-1
- from 0, < 1.3.1-1
- from 0, < 1.6.5-1
- from 0, < 1.2.3-3+squeeze11
- from 0, < 1.6.6-1
- from 0, < 1.4.5-1+deb7u8
- from 0, < 1.7.7-1
- from 0, < 1.6.6-1
- from 0, < 1.0.2-1+lenny2
- from 0, < 1.1.1-1
- from 0, < 1.1-1
- from 0, < 1.0-1
- from 0, < 2:2.2.28-1~deb11u1
- from 0, < 2:2.2.26-1~deb11u1
- from 0, < 1:1.11.29-1+deb10u3
- from 0, < 2:2.2.26-1~deb11u1
- from 0, < 2:2.2.24-1
- from 0, < 1:1.10.7-2+deb9u13
- from 0, < 2:2.2.21-1
- from 0, < 1:1.11.29-1+deb10u2
- from 0, < 2:2.2.16-1
- from 0, < 2:2.2.16-1
- from 0, < 2:2.2.4-1
- from 0, < 2:2.2.4-1
- from 0, < 3:3.2.25-0+deb12u1
- from 0, < 1:1.10.7-2+deb9u6
- from 0, < 1.7.11-1+deb8u7
- from 0, < 2:2.2.4-1
- from 0, < 1.7.9-1
- from 0, < 1.4.5-1+deb7u12
- from 0, < 1:1.11.20-1
- from 0, < 1:1.11.10-1
- from 0, < 1.2.4-1
- from 0, < 1.3.1-1
- from 0, < 1.3.1-1
- from 0, < 1.2.3-3+squeeze1
- from 0, < 1.2.5-1
- from 0, < 1.6.5-1
- from 0, < 1.4.5-1+deb7u16
- from 0, < 1.9.4-1
- from 0, < 2:2.2.25-1~deb11u1
- from 0, < 2:2.2.28-1~deb11u9
- from 0, < 2:2.2.28-1~deb11u9
- from 0, < 2:2.2.28-1~deb11u8
- from 0, < 2:2.2.28-1~deb11u8
- from 0
- MEDIUM6.5CVE-2026-33033Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file uploadfrom 0
- from 0, < 1.6.6-1
- from 0, < 2:2.2.8-1
- from 0, < 1:1.11.18-1
- from 0, < 1:1.10.7-2+deb9u4
- from 0, < 1.7.11-1+deb8u4
- from 0, < 1.2.4-1
- from 0, < 1.4.1-1
- from 0, < 1.2.3-3+squeeze3
- from 0, < 1.7.6-1
- from 0, < 1.7.1-1.1
- MEDIUM6.1CVE-2013-4249Django cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widgetfrom 0, < 1.5.2-1
- from 0, < 1.2.3-3+squeeze6
- from 0, < 1.5.2-1
- from 0, < 1.4.5-1+deb7u17
- from 0, < 1:1.9.8-1
- from 0, < 1.7.7-1+deb8u5
- from 0, < 1.7.7-1
- from 0, < 1.4.5-1+deb7u11
- from 0, < 1.2.3-3+squeeze13
- from 0, < 0.96.2-1
- from 0, < 2:2.2.28-1~deb11u1
- from 0, < 1:1.10.7-2+deb9u15
- from 0, < 2:2.2.28-1~deb11u1
- from 0, < 2:2.2.22-1
- from 0, < 2:2.2.13-1
- from 0, < 1.7.11-1+deb8u5
- from 0, < 1:1.10.7-2+deb9u5
- from 0, < 1:1.11.21-1
- from 0, < 1:1.11.5-1
- from 0, < 1:1.10.7-1
- from 0, < 1.4.22-1+deb7u3
- from 0, < 1:1.10.7-1
- from 0, < 1:1.11.15-1
- from 0, < 1:1.10.7-2+deb9u2
- from 0, < 1.2.5-1
- from 0, < 1.2.3-1
- from 0, < 2:2.2.28-1~deb11u7
- from 0, < 2:2.2.28-1~deb11u7
- from 0, < 0.95.1-1etch2
- from 0, < 0.96-1.1
- from 0, < 2:2.2.19-1
- from 0, < 1:1.10.7-2+deb9u11
- from 0, < 1.7.11-1+deb8u9
- from 0, < 2:2.2.13-1
- from 0, < 1:1.10.7-2+deb9u9
- from 0, < 2:2.2.28-1~deb11u5
- from 0, < 2:2.2.28-1~deb11u5
- from 0, < 1.9.2-1
- from 0, < 2:2.2.28-1~deb11u12
- from 0, < 2:2.2.28-1~deb11u12
- from 0, < 2:2.2.28-1~deb11u12
- MEDIUM5.3CVE-2026-5766Potential denial-of-service vulnerability in ASGI requests via file upload limit bypassfrom 0
- MEDIUM5.3CVE-2025-13473Username enumeration through timing difference in mod_wsgi authentication handlerfrom 0, < 2:2.2.28-1~deb11u12
- MEDIUM5.3CVE-2025-13473Username enumeration through timing difference in mod_wsgi authentication handlerfrom 0, < 2:2.2.28-1~deb11u12
- MEDIUM5.3CVE-2025-13473Username enumeration through timing difference in mod_wsgi authentication handlerfrom 0, < 3:3.2.25-0+deb12u2
- from 0, < 2:2.2.28-1~deb11u7
- MEDIUM5.3CVE-2024-45230Django vulnerable to denial-of-service attack via the urlize() and urlizetrunc() template filtersfrom 0
- from 0, < 2:2.2.28-1~deb11u11
- from 0
- from 0, < 2:2.2.28-1~deb11u11
- from 0, < 2:2.2.28-1~deb11u11
- from 0, < 2:2.2.28-1~deb11u11
- from 0, < 2:2.2.28-1~deb11u7
- from 0, < 2:2.2.28-1~deb11u7
- from 0, < 2:2.2.28-1~deb11u7
- from 0, < 1:1.11.29-1+deb10u10
- from 0, < 1.4.5-1+deb7u9
- from 0, < 1.7.1-1.1
- from 0, < 1.2.3-3+squeeze12
- from 0, < 1.6.6-1
- from 0, < 1.4.4-1
- from 0, < 2:2.2.26-1~deb11u1
- from 0, < 1:1.11.29-1+deb10u4
- from 0, < 2:2.2.20-1
- from 0, < 1:1.10.7-2+deb9u12
- from 0, < 1:1.11.29-1+deb10u11
- from 0, < 1:1.10.7-2+deb9u10
- from 0, < 2:2.2.18-1
- from 0, < 1.7.11-1+deb8u6
- from 0, < 1:1.11.22-1
- from 0, < 1:1.11.11-1
- from 0, < 1.7.11-1+deb8u3
- from 0, < 1.4.22-1+deb7u4
- MEDIUM5.3CVE-2018-7537Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filtersfrom 0, < 1:1.11.11-1
- from 0, < 2:2.2.28-1~deb11u6
- from 0, < 2:2.2.28-1~deb11u6
- from 0, < 1:1.10.7-2+deb9u14
- from 0, < 2:2.2.24-1
- MEDIUM4.3CVE-2026-6907Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddlewarefrom 0
- from 0, < 3:4.2.27-0+deb13u1
- from 0, < 3:3.2.25-0+deb12u1
- from 0, < 1.4.4-1
- from 0, < 2:2.2.28-1~deb11u7
- from 0, < 1.3.1-1
- from 0, < 1.2.3-3+squeeze2
- from 0
- from 0, < 2:2.2.28-1~deb11u11
- from 0, < 2:2.2.28-1~deb11u9
- from 0, < 1.9.4-1
- from 0, < 1.8.7-1
- from 0, < 1.4.5-1+deb7u14
- from 0, < 1.2.3-3+squeeze15
- from 0
- from 0, < 1.4.4-1
- from 0, < 0.95.1-1
- from 0, < 0.95.1-1
- —CVE-2007-5828Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary…from 0, < 1.2.1