Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242427
AlmaLinux
5975
Alpaquita
16176
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9501
Chainguard
1048512
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68992
Echo
7853
GHC
3
GIT
109057
GitHub Actions
55
Go
9332
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148636
npm
229266
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4344
Root
19644
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9974
Ubuntu
66090
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-4035
PyPI/django
Django GeoDjango spatial lookups allow file writes and outbound requests through GDAL raster parsing
4 days ago
Fix available
Severity - 8.7 (High)
PYSEC-2026-3824
PyPI/django-cms
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
10 Sep
Fix available
Severity - 4.8 (Medium)
PYSEC-2026-3822
PyPI/django-cms
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
10 Sep
Fix available
Severity - 7.1 (High)
PYSEC-2026-3823
PyPI/django-cms
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
10 Sep
Fix available
Severity - 4.3 (Medium)
PYSEC-2026-3821
PyPI/django-cms
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
10 Sep
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-3825
PyPI/django-cms
django CMS: Stored XSS in edit-mode plugin exception rendering
10 Sep
Fix available
Severity - 4.4 (Medium)
PYSEC-2026-3826
PyPI/django-cms
django CMS: Structure endpoint bypasses page-view permission
10 Sep
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-3820
PyPI/django-cms
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
10 Sep
Fix available
Severity - 6.5 (Medium)
GHSA-fwjf-m4qw-9f2x
PyPI/django-cms
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
24 Aug
Fix available
Severity - 4.8 (Medium)
GHSA-8jj7-4v57-frf5
PyPI/django-cms
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
24 Aug
Fix available
Severity - 7.1 (High)
GHSA-8qj2-c6q4-f399
PyPI/django-cms
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
20 Aug
Fix available
Severity - 4.3 (Medium)
GHSA-6x92-6vx4-5fwr
PyPI/django-cms
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
20 Aug
Fix available
Severity - 6.5 (Medium)
GHSA-hvq6-2r72-p2x7
PyPI/django-cms
django CMS: Stored XSS in edit-mode plugin exception rendering
20 Aug
Fix available
Severity - 4.4 (Medium)
GHSA-vgxm-h9gx-h9w7
PyPI/django-cms
django CMS: Structure endpoint bypasses page-view permission
20 Aug
Fix available
Severity - 6.5 (Medium)
GHSA-4xfr-4p46-gc6p
PyPI/django-cms
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
20 Aug
Fix available
Severity - 6.5 (Medium)
GHSA-q238-5cxm-5c9h
PyPI/django
Django GeoDjango vulnerable to denial of service through deeply nested geometry collections
04 Aug
Fix available
Severity - 6.9 (Medium)
Load more...
PyPI - OSV