Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2016-9013 python-django: user with hardcoded password created when running tests on OracleCVE-2016-9014 python-django: DNS rebinding vulnerability when 'DEBUG=True'CVE-2019-19844 Django: crafted email address allows account takeoverCVE-2020-7471 django: potential SQL injection via StringAgg(delimiter)CVE-2025-64459 django: Django SQL injectionCVE-2016-2048 python-django: user with "change" but not "add" permission can create objects for ModelAdminCVE-2016-7401 python-django: CSRF protection bypass on a site with Google AnalyticsCVE-2022-36359 An issue was discovered in the HTTP FileResponse class in Django 3.2 b ...CVE-2025-57833 django: Django SQL injection in FilteredRelation column aliasesCVE-2025-64458 Django: Denial-of-service vulnerability in Django on WindowsCVE-2016-2512 python-django: Malicious redirect and possible XSS attack via user-supplied redirect URLs containing basic authCVE-2016-6186 django: XSS in admin's add/change related popupCVE-2017-7233 python-django: Open redirect and possible XSS attack via user-supplied numeric redirect URLsCVE-2017-7234 python-django: Open redirect vulnerability in django.views.static.serve()CVE-2021-33203 django: Potential directory traversal via ``admindocs``CVE-2024-45231 python-django: Potential user email enumeration via response status on password resetCVE-2025-48432 django: Django Path Injection VulnerabilityCVE-2026-53877 django: Django: Information disclosure via heap buffer over-read in GDALRasterCVE-2026-53878 django: Django: HTTP header injection via DomainNameValidator accepting newlinesCVE-2016-2513 python-django: User enumeration through timing difference on password hasher work factor upgradeCVE-2026-48587 django: Django: Information disclosure via improper handling of Vary header whitespaceCVE-2026-48588 django: Django: Information disclosure due to improper caching of Set-Cookie responsesCVE-2026-6873 python-django: Django: Information disclosure via non-injective cookie salt derivationCVE-2026-8404 Django: Django: Information disclosure due to improper handling of Cache-Control directivesYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2016-17 Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easiPYSEC-2016-18 Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validatePYSEC-2019-16 Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of GHSA-frmv-pr5f-9mcr Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.GHSA-hmr4-m2h5-33qx SQL injection in DjangoPYSEC-2016-17 Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easiPYSEC-2016-18 Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validatePYSEC-2019-16 Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of GHSA-frmv-pr5f-9mcr Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.GHSA-hmr4-m2h5-33qx SQL injection in DjangoPYSEC-2016-14 Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option wPYSEC-2016-15 The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct croPYSEC-2016-2 Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, andPYSEC-2016-3 The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting aPYSEC-2017-10 A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an openPYSEC-2017-9 Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``djaPYSEC-2021-98 Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existPYSEC-2026-1297 Django allows enumeration of user e-mail addressesGHSA-6w2r-r2m5-xq5w Django is subject to SQL injection through its column aliasesGHSA-7xr5-9hcq-chf9 Django Improper Output Neutralization for Logs vulnerabilityGHSA-8qcx-xf44-272x Django: DomainNameValidator permits newline characters that may enable HTTP header injectionGHSA-8x94-hmjh-97hq Django vulnerable to Reflected File Download attackGHSA-crhf-3pfg-w68w Django: GDALRaster may over-read heap memory when constructed from bytesGHSA-qw25-v68c-qjf3 Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on WindowsPYSEC-2016-14 Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option wCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.