CVE-2024-11319

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:django-cms:django_cms:3.11.7:*:*:*:*:*:*:*
cpe:2.3:a:django-cms:django_cms:3.11.8:*:*:*:*:*:*:*
cpe:2.3:a:django-cms:django_cms:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:django-cms:django_cms:4.1.3:*:*:*:*:*:*:*

History

12 Sep 2025, 07:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 3.8
v2 : unknown
v3 : 4.8

Information

Published : 2024-11-18 12:15

Updated : 2025-09-12 07:15


NVD link : CVE-2024-11319

Mitre link : CVE-2024-11319

CVE.ORG link : CVE-2024-11319


JSON object : View

Products Affected

django-cms

  • django_cms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')