It was discovered that Django incorrectly handled special characters in the QuerySet function calls. A remote attacker could possibly use this issue to perform SQL injection attacks. (CVE-2025-59681) It was discovered that Django incorrectly handled files with the same path prefix when starting with a template. An attacker could possibly use this issue to obtain sensitive information. (CVE-2025-59682)
Continue reading...
Continue reading...

