GHSA-9r8w-6x8c-6jr9
GitHub Security Advisory
Django vulnerable to XSS on 500 pages
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstances, this allowed a cross-site scripting attack. This vulnerability shouldn't affect most production sites since you shouldn't run with `DEBUG = True` (which makes this page accessible) in your production settings.
Affected Packages
PyPI
Django
Affected versions:
1.10a1
(fixed in 1.10.8)
PyPI
Django
Affected versions:
1.11a1
(fixed in 1.11.5)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 3, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.