Django 1.2 lifecycle
Current status
Django 1.2 reached end of life on 11 Sept 2011. Security and bug fixes are no longer provided by the project according to published lifecycle data.
Official lifecycle source: PyPI JSON API
- Support phase
- end of life
- End of life
- 11 Sept 2011
- Latest release
- 1.2.7
- Released
- 11 Sept 2011
At a glance
- Version line
- 1.2
- Initial release
- —
- Lifecycle phase
- end of life
- Latest stable
- 1.2.7
- Latest release date
- 11 Sept 2011
- EOL
- 11 Sept 2011
- Risk
- high
- Releases tracked
- 7
Lifecycle timeline
Phases from published LifecyclePeriod records. Missing phases are not inferred.
standard support
24 May 2010 → 11 Sept 2011
Source: PyPI JSON API
end of lifecurrent
11 Sept 2011 → —
Source: PyPI JSON API
Django 1.2 reached end of life on 11 Sept 2011. Security and bug fixes are no longer provided by the project according to published lifecycle data.
Security
Advisories affecting Django 1.2 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 15
- Known exploited
- 0
- Highest CVSS
- 10.0
- CVE-2014-0474GHSA-wqjj-hx84-v449
Django Vulnerable to MySQL Injection
- CVSS:
- 10.0 · NVD
- CWE:
- CWE-399
- Affected:
- <1.4.11
- Fixed in:
- 1.4.11
- Source:
- OSV source · Advisory
- CVE-2020-7471GHSA-hmr4-m2h5-33qx
SQL injection in Django
- CVSS:
- 9.8 (critical) · NVD
- CWE:
- CWE-89
- Affected:
- <1.11.28
- Fixed in:
- 1.11.28
- Source:
- OSV source · Advisory
- CVE-2025-64459GHSA-frmv-pr5f-9mcr
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
- CVSS:
- 9.1 (critical) · NVD
- CWE:
- CWE-89
- Affected:
- <4.2.26
- Fixed in:
- 4.2.26
- Source:
- OSV source · Advisory
- CVE-2022-36359GHSA-8x94-hmjh-97hq
Django vulnerable to Reflected File Download attack
- CVSS:
- 8.8 (high) · NVD
- CWE:
- CWE-494
- Affected:
- <3.2.15
- Fixed in:
- 3.2.15
- Source:
- OSV source · Advisory
- CVE-2025-57833GHSA-6w2r-r2m5-xq5w
Django is subject to SQL injection through its column aliases
- CVSS:
- 8.1 (high) · NVD
- CWE:
- CWE-89
- Affected:
- <4.2.24
- Fixed in:
- 4.2.24
- Source:
- OSV source · Advisory
- CVE-2025-64458GHSA-qw25-v68c-qjf3
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-407
- Affected:
- <4.2.26
- Fixed in:
- 4.2.26
- Source:
- OSV source · Advisory
- CVE-2016-7401GHSA-crhm-qpjc-cm64
Django CSRF Protection Bypass
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-254
- Affected:
- <1.8.15
- Fixed in:
- 1.8.15
- Source:
- OSV source · Advisory
- CVE-2016-2512GHSA-pw27-w7w4-9qc7
Django XSS Vulnerability
- CVSS:
- 7.4 (high) · NVD
- CWE:
- CWE-79
- Affected:
- <1.8.10
- Fixed in:
- 1.8.10
- Source:
- OSV source · Advisory
- CVE-2011-0696GHSA-5j2h-h5hg-3wf8
Cross-site request forgery in Django
- CVSS:
- 6.8 · NVD
- CWE:
- CWE-352
- Affected:
- >=1.2,<1.2.5
- Fixed in:
- 1.2.5
- Source:
- OSV source · Advisory
- CVE-2011-0696PYSEC-2011-10
- CVSS:
- 6.8 · NVD
- CWE:
- CWE-352
- Affected:
- >=1.2,<1.2.5
- Fixed in:
- 1.2.5
- Source:
- OSV source · Advisory
- CVE-2026-53878GHSA-8qcx-xf44-272x
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
- CVSS:
- 6.1 (moderate) · NVD
- CWE:
- CWE-144
- Affected:
- <5.2.16
- Fixed in:
- 5.2.16
- Source:
- OSV source · Advisory
- CVE-2016-6186GHSA-c8c8-9472-w52h
Django Cross-site scripting Vulnerability
- CVSS:
- 6.1 (moderate) · NVD
- CWE:
- CWE-79
- Affected:
- <1.8.14
- Fixed in:
- 1.8.14
- Source:
- OSV source · Advisory
- CVE-2014-0482GHSA-625g-gx8c-xcmg
Django Middleware Enables Session Hijacking
- CVSS:
- 6.0 · NVD
- CWE:
- CWE-287
- Affected:
- <1.4.14
- Fixed in:
- 1.4.14
- Source:
- OSV source · Advisory
- CVE-2014-0480GHSA-f7cm-ccfp-3q4r
Django Incorrectly Validates URLs
- CVSS:
- 5.8 · NVD
- CWE:
- CWE-20
- Affected:
- <1.4.14
- Fixed in:
- 1.4.14
- Source:
- OSV source · Advisory
- CVE-2026-48588GHSA-3h9f-r86x-qvjx
Django: cache middleware may expose private responses when unrelated request cookies are present
- CVSS:
- 5.3 (moderate) · NVD
- CWE:
- CWE-524
- Affected:
- <5.2.16
- Fixed in:
- 5.2.16
- Source:
- OSV source · Advisory
Latest release
Previous releases
1.2.6
10 Sept 2011
1.2.5
9 Feb 2011
1.2.4
23 Dec 2010
Release history
7 concrete releases tracked for this line.
Release activity
- Total releases
- 7
- Last 30 days
- 0
- Last 90 days
- 0
- Avg. interval
- ~79 days
- Most recent
- 11 Sept 2011
Should I use this version?
Not recommended for new deployments
Upgrade to a currently supported release line. Recommended target: Django 6.1.
Upgrade options
Newer supported Django version lines from CompatHub lifecycle data. Compatibility and security context use existing evidence only.
You are on Django 1.2
End of lifeEOL 11 September 2011
Supported upgrade options
- Django 5.2Upgrade planner →SupportedEOL 1 April 2028· ~198 months more support· 4 major versions newer
- Django 6.1Upgrade planner →SupportedEOL 1 December 2027· ~194 months more support· 5 major versions newer
- Django 6.0Upgrade planner →SupportedEOL 1 April 2027· ~186 months more support· 5 major versions newer
Version comparison
Compact comparison against the nearest relevant release lines.
Sources
Where this information comes from.
Lifecycle sources
- PyPI JSON APIfirst party · high confidence
Official source: https://pypi.org
Last verified 1 Sept 2026
- OSV.devfirst party
Official source: https://osv.dev
Verification time not recorded
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Verification time not recorded
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Verification time not recorded
Release sources
- PyPI JSON APIfirst party · high confidence
Official source: https://pypi.org
Last verified 1 Sept 2026
- Django Download / Support Schedulefirst party
Official source: https://www.djangoproject.com/download/
Verification time not recorded
Data coverage
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Releases tracked
- 7
- Lifecycle periods
- 2
- EOL
- Known
- Provenance records
- 3
- Data last checked
- 1 Sept 2026
- Latest source update
- 1 Sept 2026
