Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-fwjf-m4qw-9f2x
  • PyPI/django-cms
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) 24 Aug
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-8jj7-4v57-frf5
  • PyPI/django-cms
django CMS: Plugin move endpoint allows cyclic reparenting (DoS) 24 Aug
  • Fix available
  • Severity - 7.1 (High)
GHSA-8qj2-c6q4-f399
  • PyPI/django-cms
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff 20 Aug
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-6x92-6vx4-5fwr
  • PyPI/django-cms
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass) 20 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-hvq6-2r72-p2x7
  • PyPI/django-cms
django CMS: Stored XSS in edit-mode plugin exception rendering 20 Aug
  • Fix available
  • Severity - 4.4 (Medium)
GHSA-vgxm-h9gx-h9w7
  • PyPI/django-cms
django CMS: Structure endpoint bypasses page-view permission 20 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-4xfr-4p46-gc6p
  • PyPI/django-cms
django CMS: Clipboard copy IDOR discloses unauthorized plugin content 20 Aug
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3717
  • PyPI/django
See record for full details 04 Aug
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-r3hx-x5rh-p9vv
  • PyPI/django-haystack
django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization 15 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-2450
  • PyPI/django-mdeditor
django-mdeditor is Missing Authentication for Critical Function 13 Jul
  • No fix available
  • Severity - 2.0 (Low)
PYSEC-2026-2451
  • PyPI/django-unicorn
django-unicorn affected by component state manipulation via unvalidated attribute access 13 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-2449
  • PyPI/django
Django has a Race Condition vulnerability 13 Jul
  • Fix available
  • Severity - 3.7 (Low)
PYSEC-2026-2448
  • PyPI/django
Django vulnerable to Uncontrolled Resource Consumption 13 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1932
  • PyPI/social-auth-app-django
Python Social Auth - Django has unsafe account association 07 Jul
  • Fix available
  • Severity - 6.3 (Medium)
PYSEC-2026-1296
  • PyPI/django
Django vulnerable to partial directory traversal via archives 07 Jul
  • Fix available
  • Severity - 3.1 (Low)
PYSEC-2026-1300
  • PyPI/django-select2
Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking 07 Jul
  • Fix available
  • Severity - 8.2 (High)