← Back

Django Unicorn

django-unicorn

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Unicorn
unicorn

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Django Unicorn
1Unicorn
Jun 17, 2026
Mar 10, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-unicorn due to missing access control checks during property updates and...Show more
Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-unicorn due to missing access control checks during property updates and method calls. An attacker can bypass the intended _is_public protection to modify internal attributes such as template_name or trigger protected methods. This vulnerability is fixed in 0.67.0.Show less
1Django Unicorn
1Unicorn
Jun 17, 2026
Oct 11, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053.
1Django Unicorn
1Unicorn
Jun 17, 2026
Oct 7, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.