CVE-2026-1312 | Django up to 4.2.27/5.2.10/6.0.1 QuerySet.order_by sql injection (Nessus ID 297744 / WID-SEC-2026-0297)
A vulnerability categorized as critical has been discovered in Django up to 4.2.27/5.2.10/6.0.1. The impacted element is an unknown function. Such manipulation of the argument QuerySet.order_by leads to sql injection.
This vulnerability is listed as CVE-2026-1312. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.