Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping.
{
"github_reviewed": true,
"severity": "MODERATE",
"cwe_ids": [
"CWE-79"
],
"nvd_published_at": "2022-07-23T02:15:00Z",
"github_reviewed_at": "2023-07-25T20:00:40Z"
}