Known vulnerabilities in Django 2.2.11

Software: Django
Version: 2.2.11
Software CPE: cpe:2.3:a:django_software_foundation:django:*:*:*:*:*:*:*:*
Total vulnerabilities: 19
Public exploits: 4
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Django version 2.2.11 Django 2.2.11 is affected by 19 vulnerabilities: 4 high, 12 medium, 3 low Critical High Medium Low

Vulnerabilities (19)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU62051 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-28347
CWE-89 High
No
No
2.2.28, 3.2.13, 4.0.4 11.04.2022 SB2022041110
SB2022041125
SB2022041267
and 8 more
#VU62050 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-28346
CWE-89 High
Public exploit available
No
2.2.28, 3.2.13, 4.0.4 11.04.2022 SB2022041110
SB2022041125
SB2022041126
and 14 more
#VU60198 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-23833
CWE-835 Medium
No
No
2.2.27, 3.2.12, 4.0.2 01.02.2022 SB2022020110
SB2022041954
SB2022020334
and 11 more
#VU60197 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-22818
CWE-79 Medium
Public exploit available
No
2.2.27, 3.2.12, 4.0.2 01.02.2022 SB2022020110
SB2022041954
SB2022020334
and 12 more
#VU59181 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-45452
CWE-22 Low
No
No
2.2.26, 3.2.11, 4.0.1 04.01.2022 SB2022010412
SB2022031201
SB2022011843
and 7 more
#VU59180 -
CVE-2021-45116
Low
No
No
2.2.26, 3.2.11, 4.0.1 04.01.2022 SB2022010412
SB2022031201
SB2022011843
and 6 more
#VU59179 - Resource Management Errors
CVE-2021-45115
CWE-399 Medium
No
No
2.2.26, 3.2.11, 4.0.1 04.01.2022 SB2022010412
SB2022031201
SB2022011843
and 6 more
#VU58552 - Improper Access Control
CVE-2021-44420
CWE-284 Medium
No
No
2.2.25, 3.1.14, 3.2.10 07.12.2021 SB2021120704
SB2021120728
SB2023051109
and 2 more
#VU53742 - Server-Side Request Forgery (SSRF)
CVE-2021-33571
CWE-918 Medium
No
No
2.2.24, 3.1.12, 3.2.4 02.06.2021 SB2021060208
SB2021061516
SB2021060234
and 5 more
#VU53741 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-33203
CWE-22 Medium
No
No
2.2.24, 3.1.12, 3.2.4 02.06.2021 SB2021060208
SB2021061516
SB2021060234
and 6 more
#VU52942 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2021-32052
CWE-113 Medium
No
No
2.2.22, 3.1.10, 3.2.2 06.05.2021 SB2021050627
SB2022041125
SB2022041126
and 7 more
#VU52842 - Unrestricted Upload of File with Dangerous Type
CVE-2021-31542
CWE-434 High
No
No
2.2.21, 3.1.9, 3.2.1 04.05.2021 SB2021050411
SB2021111919
SB2021050433
and 7 more
#VU51936 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-28658
CWE-22 Medium
No
No
2.2.20, 3.0.14, 3.1.8 06.04.2021 SB2021040605
SB2021040630
SB2021121031
and 3 more
#VU50814 - Improper input validation
CVE-2021-23336
CWE-20 Medium
No
No
2.2.19, 3.0.13, 3.1.7 19.02.2021 SB2021021907
SB2021022001
SB2021022706
and 56 more
#VU50172 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-3281
CWE-22 High
Public exploit available
No
2.2.18, 3.0.12, 3.1.6 01.02.2021 SB2021020117
SB2021020612
SB2021080213
and 7 more
#VU46660 - Incorrect Default Permissions
CVE-2020-24584
CWE-276 Medium
No
No
2.2.16, 3.0.10, 3.1.1 11.09.2020 SB2020091027
SB2020091118
SB2020121611
and 5 more
#VU46659 - Incorrect Default Permissions
CVE-2020-24583
CWE-276 Medium
No
No
2.2.16, 3.0.10, 3.1.1 11.09.2020 SB2020091027
SB2020091118
SB2020121610
and 5 more
#VU28954 - Improper Certificate Validation
CVE-2020-13254
CWE-295 Medium
Public exploit available
No
2.2.13, 3.0.7 10.06.2020 SB2020061040
SB2020061041
SB2020121608
and 5 more
#VU28953 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-13596
CWE-79 Low
No
No
2.2.13, 3.0.7 10.06.2020 SB2020061040
SB2020061041
SB2020121609
and 4 more