Filtered by vendor Django-rest-framework Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-25045 1 Django-rest-framework 1 Django Rest Framework 2024-08-05 6.1 Medium
Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping.
CVE-2024-21520 2 Django-rest-framework, Redhat 2 Django Rest Framework, Ansible Automation Platform 2024-08-01 6.1 Medium
Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags.