References https://www.anquanke.com/post/id/313045 https://www.cnblogs.com/hetianlab/p/17412566.html https://github.com/SurfRid3r/Django_vulnerability_analysis https://nic.seu.edu.cn/info/1047/1200.htm https://cloud.tencent.com/developer/article/2592963 https://mdr.skyeye.qianxin.com/forum/share/1923 https://www.anquanke.com/post/id/313545 https://avd.aliyun.com/detail?id=AVD-2022-34265 https://www.uvsec.com/news/baike/185.html https://windeskybb.work/archives/50a4cf97-d02b-4fbb-9cde-795f509fef9a https://juejin.cn/post/7231722969990201399 https://www.twcert.org.tw/tw/cp-104-6272-78eb5-1.html http://nic.qust.edu.cn/info/1018/1989.htm https://xxhzx.web.hebust.edu.cn/wlaq/361467ace8354f6183c63a93a0d881a4.htm https://www.endorlabs.com/learn/critical-sql-injection-vulnerability-in-django-cve-2025-64459 https://nvd.nist.gov/vuln/detail/CVE-2025-57833 https://zeropath.com/blog/cve-2025-57833-django-filteredrelation-sql-injection https://www.exploit-db.com/exploits/52456 https://github.com/advisories/GHSA-6w2r-r2m5-xq5w https://www.djangoproject.com/weblog/2025/nov/05/security-releases/
Related VulnerabilitiesPoCCVE-2026-1207: Django RasterField - SQL InjectionDjango 需授权 SQL注入漏洞Django 未授权 SQL注入漏洞PoCCVE-2022-34265: Django - SQL injectionPoCCVE-2017-12794: Django Debug Page - Cross-Site ScriptingPoCCVE-2018-14574: Django - Open RedirectPoCCVE-2020-9402: Django SQL InjectionPoCdjango-framework-exceptions: Django Framework ExceptionsPoCdjango-secret-key: Django Secret Key ExposurePoCdjango-debug-exposure: Django Debug ExposurePoCdjango-debug-config-enabled: Django Debug Configuration Enabled