Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2144633
AlmaLinux
5746
Alpaquita
14285
Alpine
4585
Android
3667
Azure Linux
16005
BellSoft Hardened Containers
738
Bitnami
9128
Chainguard
1002997
CleanStart
3761
CRAN
14
crates.io
2693
Debian
65518
Echo
8840
GHC
3
GIT
103255
GitHub Actions
55
Go
8988
Hackage
32
Hex
329
Julia
1713
Linux
28061
Mageia
6160
Maven
6958
MinimOS
137994
npm
228235
NuGet
1852
opam
29
openEuler
8374
openSUSE
14195
OSS-Fuzz
3991
Packagist
6989
Pub
11
PyPI
24801
Red Hat
22826
Rocky Linux
4132
Root
19255
RubyGems
4709
SUSE
22589
SwiftURL
59
TuxCare
8908
Ubuntu
62500
VSCode
21
Wolfi
279632
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-fwjf-m4qw-9f2x
PyPI/django-cms
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
24 Aug
Fix available
Severity - 4.8 (Medium)
GHSA-8jj7-4v57-frf5
PyPI/django-cms
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
24 Aug
Fix available
Severity - 7.1 (High)
GHSA-8qj2-c6q4-f399
PyPI/django-cms
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
20 Aug
Fix available
Severity - 4.3 (Medium)
GHSA-6x92-6vx4-5fwr
PyPI/django-cms
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
20 Aug
Fix available
Severity - 6.5 (Medium)
GHSA-hvq6-2r72-p2x7
PyPI/django-cms
django CMS: Stored XSS in edit-mode plugin exception rendering
20 Aug
Fix available
Severity - 4.4 (Medium)
GHSA-vgxm-h9gx-h9w7
PyPI/django-cms
django CMS: Structure endpoint bypasses page-view permission
20 Aug
Fix available
Severity - 6.5 (Medium)
GHSA-4xfr-4p46-gc6p
PyPI/django-cms
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
20 Aug
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-3717
PyPI/django
See record for full details
04 Aug
Fix available
Severity - 6.9 (Medium)
GHSA-r3hx-x5rh-p9vv
PyPI/django-haystack
django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization
15 Jul
Fix available
Severity - 8.7 (High)
PYSEC-2026-2450
PyPI/django-mdeditor
django-mdeditor is Missing Authentication for Critical Function
13 Jul
No fix available
Severity - 2.0 (Low)
PYSEC-2026-2451
PyPI/django-unicorn
django-unicorn affected by component state manipulation via unvalidated attribute access
13 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-2449
PyPI/django
Django has a Race Condition vulnerability
13 Jul
Fix available
Severity - 3.7 (Low)
PYSEC-2026-2448
PyPI/django
Django vulnerable to Uncontrolled Resource Consumption
13 Jul
Fix available
Severity - 7.5 (High)
PYSEC-2026-1932
PyPI/social-auth-app-django
Python Social Auth - Django has unsafe account association
07 Jul
Fix available
Severity - 6.3 (Medium)
PYSEC-2026-1296
PyPI/django
Django vulnerable to partial directory traversal via archives
07 Jul
Fix available
Severity - 3.1 (Low)
PYSEC-2026-1300
PyPI/django-select2
Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
07 Jul
Fix available
Severity - 8.2 (High)
Load more...
PyPI - OSV