CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-15307

highCVSS 8.8covered by 2 sourcesfirst seen 2026-08-04
An attacker can exploit multiple vulnerabilities in Django to execute arbitrary code, manipulate data, perform cross-site scripting attacks, or trigger a denial of service condition.

CSIRTS triage

What
Multiple vulnerabilities in Django enable arbitrary code execution, data manipulation, cross-site scripting, and denial of service.
Who is affected
Any application running vulnerable Django versions and handling untrusted input is affected.
Urgency
High severity with multiple attack vectors including code execution requires immediate patching regardless of deployment exposure.
Action
Update Django to the latest patched version without delay.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-15307

Get an email if CVE-2026-15307 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-15307

CVE.org record

Embed the live status

CVE-2026-15307 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-15307 status](https://www.csirts.com/badge/CVE-2026-15307)](https://www.csirts.com/cve/CVE-2026-15307)