{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-15920","assignerOrgId":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92","state":"PUBLISHED","assignerShortName":"DSF","dateReserved":"2026-07-15T20:32:49.882Z","datePublished":"2026-08-04T15:48:40.537Z","dateUpdated":"2026-08-04T17:21:13.428Z"},"containers":{"cna":{"providerMetadata":{"orgId":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92","shortName":"DSF","dateUpdated":"2026-08-04T15:48:40.537Z"},"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-83","description":"CWE-83: Improper Neutralization of Script in Attributes in a Web Page","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-244","descriptions":[{"lang":"en","value":"CAPEC-244: XSS Targeting URI Placeholders"}]}],"title":"Potential cross-site scripting via URLField values in the admin","metrics":[{"other":{"content":{"value":"moderate","namespace":"https://docs.djangoproject.com/en/dev/internals/security/#security-issue-severity-levels"},"type":"Django severity rating"}},{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM"}},{"cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","baseScore":5.1,"baseSeverity":"MEDIUM"}}],"descriptions":[{"lang":"en","value":"An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.\n`django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link.\r\nExploitation requires the unsafe value to already be stored in the database. `URLField` validation through a `ModelForm` or the admin rejects unsafe schemes, so this affects applications that persist `URLField` data without running model validation, for example through direct queryset writes, deserialization, or bulk import of untrusted input.\nDjango would like to thank Egor Saltykov for reporting this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.</p><p><code>django.contrib.admin.utils.display_for_field()</code> renders <code>URLField</code> values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link.</p><p>Exploitation requires the unsafe value to already be stored in the database. <code>URLField</code> validation through a <code>ModelForm</code> or the admin rejects unsafe schemes, so this affects applications that persist <code>URLField</code> data without running model validation, for example through direct queryset writes, deserialization, or bulk import of untrusted input.</p><p>Django would like to thank Egor Saltykov for reporting this issue.</p>"}]}],"affected":[{"collectionURL":"https://pypi.org/project/Django/","defaultStatus":"unaffected","packageName":"django","product":"Django","repo":"https://github.com/django/django/","vendor":"djangoproject","versions":[{"status":"affected","version":"6.0","lessThan":"6.0.8","versionType":"python"},{"status":"unaffected","version":"6.0.8","versionType":"python"},{"status":"affected","version":"5.2","lessThan":"5.2.17","versionType":"python"},{"status":"unaffected","version":"5.2.17","versionType":"python"}]}],"references":[{"url":"https://docs.djangoproject.com/en/dev/releases/security/","name":"Django security archive","tags":["vendor-advisory"]},{"url":"https://groups.google.com/g/django-announce","name":"Django releases announcements","tags":["mailing-list"]},{"tags":["patch"],"url":"https://github.com/django/django/commit/47511a21026cdd721d8fbf8571cc079bc38bb46d"},{"tags":["patch"],"url":"https://github.com/django/django/commit/5a260d309a4c8010c2ebda24eb758a5d95e2508a"},{"tags":["patch"],"url":"https://github.com/django/django/commit/13debb622a32720bda1bccda7622fd14fbf3931b"},{"tags":["patch"],"url":"https://github.com/django/django/commit/b9adb81339cc418f8f56b1050cca6dfec3ab6349"},{"url":"https://www.djangoproject.com/weblog/2026/aug/04/security-releases/","name":"Django security releases issued: 6.0.8 and 5.2.17","tags":["vendor-advisory"]}],"credits":[{"lang":"en","type":"reporter","value":"Egor Saltykov"},{"lang":"en","type":"remediation developer","value":"Natalia Bidart"},{"lang":"en","type":"coordinator","value":"Natalia Bidart"}],"timeline":[{"lang":"en","time":"2026-07-13T00:00:00.000Z","value":"Initial report received."},{"lang":"en","time":"2026-07-21T00:00:00.000Z","value":"Vulnerability confirmed."},{"lang":"en","time":"2026-08-04T10:00:00.000Z","value":"Security release issued."}],"datePublic":"2026-08-04T10:00:00.000Z","source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-04T17:16:24.319084Z","id":"CVE-2026-15920","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-04T17:21:13.428Z"}}]}}