๐Ÿ” CVE Alert

CVE-2026-15920

MEDIUM 6.1

Potential cross-site scripting via URLField values in the admin

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link. Exploitation requires the unsafe value to already be stored in the database. `URLField` validation through a `ModelForm` or the admin rejects unsafe schemes, so this affects applications that persist `URLField` data without running model validation, for example through direct queryset writes, deserialization, or bulk import of untrusted input. Django would like to thank Egor Saltykov for reporting this issue.

CWE CWE-83
Vendor djangoproject
Product django
Published Aug 4, 2026
Last Updated Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for djangoproject django

Be the first to know when new medium vulnerabilities affecting djangoproject django are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

djangoproject / Django
6.0 < 6.0.8 5.2 < 5.2.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.djangoproject.com: https://docs.djangoproject.com/en/dev/releases/security/ groups.google.com: https://groups.google.com/g/django-announce github.com: https://github.com/django/django/commit/47511a21026cdd721d8fbf8571cc079bc38bb46d github.com: https://github.com/django/django/commit/5a260d309a4c8010c2ebda24eb758a5d95e2508a github.com: https://github.com/django/django/commit/13debb622a32720bda1bccda7622fd14fbf3931b github.com: https://github.com/django/django/commit/b9adb81339cc418f8f56b1050cca6dfec3ab6349 djangoproject.com: https://www.djangoproject.com/weblog/2026/aug/04/security-releases/

Credits

๐Ÿ” Egor Saltykov Natalia Bidart Natalia Bidart