CVE-2026-15920

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
04/08/2026
Last modified:
17/08/2026

Description

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.<br /> `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link.<br /> Exploitation requires the unsafe value to already be stored in the database. `URLField` validation through a `ModelForm` or the admin rejects unsafe schemes, so this affects applications that persist `URLField` data without running model validation, for example through direct queryset writes, deserialization, or bulk import of untrusted input.<br /> Django would like to thank Egor Saltykov for reporting this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* 5.2 (including) 5.2.17 (excluding)
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* 6.0 (including) 6.0.8 (excluding)