CVE-2016-6186: Debian Linux

Medium severity, CVSS 6.1. EPSS: 5.6% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to inject arbitrary web script or HTML via vectors involving unsafe usage of Element.innerHTML.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Djangoproject Django: up to and including 1.8.13; version 1.9 only; version 1.9.0 only; version 1.9.1 only; version 1.9.2 only; version 1.9.3 only; …

Published 2016-08-05. Last modified 2026-06-17.