Known CVEs in Django framework
pathfinder scan --ruleset cpf/python/django-cve
Detects SQL injection where user input flows to cursor.execute() without proper parameterization