0.006 Low
EPSS
Percentile
79.2%
The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.
docs.djangoproject.com/en/4.0/releases/security/
github.com/advisories/GHSA-95rw-fx8r-36v6
groups.google.com/forum/#!forum/django-announce
www.djangoproject.com/weblog/2022/feb/01/security-releases/