Skip to content

Known CVE

Django RasterField - SQL Injection

Django < 6.0.2, < 5.2.11, and < 4.2.28 contains a SQL injection caused by improper sanitization of the band index parameter in RasterField on PostGIS, letting remote attackers inject SQL, exploit requires crafted input.

CVE-2026-1207

High2026CVSS 8.1CWE-89

cve2026 · django · sqli · postgis · rasterfield · vuln · unauth · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website