Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-15920

Gravedad CVSS v4.0:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
04/08/2026
Última modificación:
17/08/2026

Descripción

*** Pendiente de traducción *** An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.<br /> `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link.<br /> Exploitation requires the unsafe value to already be stored in the database. `URLField` validation through a `ModelForm` or the admin rejects unsafe schemes, so this affects applications that persist `URLField` data without running model validation, for example through direct queryset writes, deserialization, or bulk import of untrusted input.<br /> Django would like to thank Egor Saltykov for reporting this issue.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* 5.2 (incluyendo) 5.2.17 (excluyendo)
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* 6.0 (incluyendo) 6.0.8 (excluyendo)