<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Django — PoC Archive</title><link>https://poc.intelseclab.com/tags/django/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/django/index.xml" rel="self" type="application/rss+xml"/><item><title>XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-54322-xspeeder-sxzos-preauth-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-54322-xspeeder-sxzos-preauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-54322. Status: Weaponized. Affects: XSpeeder SXZOS firmware (SD-WAN devices, routers, edge networking equipment). Tags: xspeeder, sxzos, sd-wan, router, firmware, python, django, eval-injection, pre-auth, rce, cwe-95.</description><category>network</category><category>Critical</category><category>xspeeder</category><category>sxzos</category><category>sd-wan</category><category>router</category><category>firmware</category><category>python</category><category>django</category><category>eval-injection</category><category>pre-auth</category><category>rce</category><category>cwe-95</category></item><item><title>Django QuerySet/Q Object SQL Injection via `_connector` Kwarg (CVE-2025-64459)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-64459-django-queryset-connector-sqli/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-64459-django-queryset-connector-sqli/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-64459. Status: Weaponized. Affects: Django ORM (QuerySet.filter() / Q object construction). Tags: django, python, sql-injection, queryset, q-object, orm, cwe-89, data-exposure, sqlite.</description><category>web</category><category>Critical</category><category>django</category><category>python</category><category>sql-injection</category><category>queryset</category><category>q-object</category><category>orm</category><category>cwe-89</category><category>data-exposure</category><category>sqlite</category></item><item><title>Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25964-tandoor-recipes-lfi/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25964-tandoor-recipes-lfi/</guid><description>Medium severity (CVSS 4.9) — web · CVE-2026-25964 (GHSA-6485-jr28-52xx). Status: PoC. Affects: Tandoor Recipes (self-hosted recipe manager, Django-based). Tags: path-traversal, local-file-disclosure, tandoor-recipes, django, rest-api, authenticated, cwe-22, arbitrary-file-read.</description><category>web</category><category>Medium</category><category>path-traversal</category><category>local-file-disclosure</category><category>tandoor-recipes</category><category>django</category><category>rest-api</category><category>authenticated</category><category>cwe-22</category><category>arbitrary-file-read</category></item><item><title>Django MultiPartParser Base64 Whitespace CPU Amplification DoS — CVE-2026-33033</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33033-django-multipartparser-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33033-django-multipartparser-dos/</guid><description>Medium severity — web · CVE-2026-33033. Status: PoC. Affects: Django (django.http.multipartparser.MultiPartParser). Tags: django, dos, multipart, base64, cpu-amplification, python, file-upload.</description><category>web</category><category>Medium</category><category>django</category><category>dos</category><category>multipart</category><category>base64</category><category>cpu-amplification</category><category>python</category><category>file-upload</category></item><item><title>Django GIS RasterField SQL Injection (CVE-2026-1207)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1207-django-gis-rasterfield-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1207-django-gis-rasterfield-sqli/</guid><description>High severity — web · CVE-2026-1207. Status: PoC. Affects: Django django.contrib.gis (GeoDjango) RasterField queries. Tags: django, gis, geodjango, sql-injection, rasterfield, postgis, python.</description><category>web</category><category>High</category><category>django</category><category>gis</category><category>geodjango</category><category>sql-injection</category><category>rasterfield</category><category>postgis</category><category>python</category></item></channel></rss>