Known CVE
Django RasterField - SQL Injection
Django < 6.0.2, < 5.2.11, and < 4.2.28 contains a SQL injection caused by improper sanitization of the band index parameter in RasterField on PostGIS, letting remote attackers inject SQL, exploit requires crafted input.
CVE-2026-1207
High2026CVSS 8.1CWE-89
cve2026 · django · sqli · postgis · rasterfield · vuln · unauth · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website