Looking for the vulnerability index of Invicti's legacy products?
Django Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2025-59681 - Vulnerability Database

Django Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2025-59681

Critical
Reference: CVE-2025-59681
Title: Django Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

An issue was discovered in Django 4.2 before 4.2.25 5.1 before 5.1.13 and 5.2 before 5.2.7. QuerySet.annotate() QuerySet.alias() QuerySet.aggregate() and QuerySet.extra() are subject to SQL injection in column aliases when using a suitably crafted dictionary with dictionary expansion as the kwargs passed to these methods (on MySQL and MariaDB).