djangoproject django
153 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
django.middleware.cache.UpdateCacheMiddleware erroneously cacContent-Length heASGIRequest allows a remote attacker to sMultiPartParser allows remote attackers tURLField.to_python() in Django calls `url.QuerySet.order_by() is subject to SQL inFilteredRelation is subject to SQL injectdjango.utils.text.Truncator.chars() and `RasterField` (only impASGIRequest allows a remote attacker to cFilteredRelation is subject to SQL injectQuerySet.filter(), `QuerySet.