Exposição de Django
Web frameworks58
score de exposição
25.842
sites usam
0
em exploração
2
críticos
Análise Vexday
O histórico de vulnerabilidades catalogadas para o Django totaliza 33 CVEs, das quais nenhuma consta atualmente no catálogo CISA KEV, taxa abaixo da média geral do catálogo — o que indica ausência de exploração ativa confirmada no momento. Ainda assim, o volume recente merece atenção: 13 CVEs surgiram nos últimos 90 dias, sinalizando um ritmo elevado de descobertas recentes. O tipo de falha mais comum é CWE-89 (injeção de SQL), e a CVE mais perigosa ativa hoje, CVE-2025-64459, apresenta EPSS de 0,1914 — probabilidade não desprezível de exploração que, somada às 2 CVEs de severidade crítica no portfólio, recomenda atenção contínua ao ciclo de atualização em ambientes que utilizam o framework.
CVEs
40 resultadosCVE-2025-59681HIGHAn issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySeEPSS 0.6%CVE-2026-35192LOWSession fixation via public cached pages and SESSION_SAVE_EVERY_REQUESTEPSS 0.5%CVE-2026-15307HIGHServer-side file-write and request forgery via spatial lookupsEPSS 0.5%CVE-2026-15830MEDIUMPotential denial-of-service vulnerability via nested geometry collectionsEPSS 0.5%CVE-2026-15337MEDIUMPotential denial-of-service vulnerability in check_for_language()EPSS 0.5%CVE-2026-4277CRITICALPrivilege abuse in GenericInlineModelAdminEPSS 0.5%CVE-2026-3902HIGHASGI header spoofing via underscore/hyphen conflationEPSS 0.4%CVE-2026-5766MEDIUMPotential denial-of-service vulnerability in ASGI requests via file upload limit bypassEPSS 0.4%CVE-2026-48588LOWPotential exposure of private data via cached Set-Cookie responseEPSS 0.4%CVE-2026-35193LOWPotential exposure of private data via missing Vary: Authorization in UpdateCacheMiddlewareEPSS 0.4%CVE-2026-6907LOWPotential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddlewareEPSS 0.4%CVE-2026-48587LOWPotential exposure of private data via whitespace padding in Vary headerEPSS 0.4%CVE-2026-25674LOWPotential incorrect permissions on newly created file system objectsEPSS 0.3%CVE-2026-15920MEDIUMPotential cross-site scripting via URLField values in the adminEPSS 0.3%CVE-2026-4292LOWPrivilege abuse in ModelAdmin.list_editableEPSS 0.3%CVE-2026-8404LOWPotential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddlewareEPSS 0.3%CVE-2026-53877MEDIUMHeap buffer over-read in GDALRasterEPSS 0.3%CVE-2026-6873LOWSigned cookie salt namespace collision in django.http.HttpRequest.get_signed_cookieEPSS 0.2%CVE-2026-53878MEDIUMHeader injection possibility since DomainNameValidator accepted newlines in inputEPSS 0.2%CVE-2026-7666LOWPotential unencrypted email transmission via STARTTLS in the SMTP backendEPSS 0.1%