What is CVE-2026-15920?
This vulnerability allows stored XSS in Django's admin via an unvalidated URLField display path. Django users must update immediately to prevent malicious script execution through untrusted URLs in the admin interface.
Azərbaycanca: Bu zəiflik Django admin panelində saxlanılan XSS hücumuna imkan verir — təsdiqlənməmiş URLField-in göstərilməsi yolu ilə. Django istifadəçiləri admin panelə etibarlı olmayan URL daxil edə bilən hər kəsdən qorunmaq üçün dərhal yeniləmə tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
How does CVE-2026-15920 affect the Django admin panel?
This vulnerability allows stored XSS in Django's admin via an unvalidated URLField display path, enabling the execution of malicious scripts through untrusted URLs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.