Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2023-40027 Keystone is an open source headless CMS for Node.js — built with GraphQL and React. When `ui.isAccessAllowed` is set as `undefined`, the `adminMeta` … Keystone 5.5.1+ Fix from $1,6002023-08-15 CRITICAL 9.8 CVE-2022-39382 Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/[email protected] || 3.0.1` users that use `NODE_ENV` to trigger security… Keystone Patch available Fix from $2,3002022-11-03 CRITICAL 9.8 CVE-2022-39322 @keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, u… Keystone 2.3.1+ Fix from $2,3002022-10-25 CRITICAL 9.8 CVE-2022-29354 An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file. Keystone No fix yet Fix from $2,3002022-05-16 MEDIUM 6.1 CVE-2022-0087 keystone is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Keystone 1.0.2+ Fix from $1,6002022-01-12 MEDIUM 5.3 CVE-2021-32624 Keystone 5 is an open source CMS platform to build Node.js applications. This security advisory relates to a newly discovered capability in our query… Keystone 5 after 19.3.2 Fix from $1,6002021-05-24 HIGH 7.5 CVE-2015-9240 Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A corre… Keystone 0.3.16+ Fix from $1,9502018-05-29 HIGH 8.8 CVE-2017-16570 KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_… Keystone 4.0.0+ Fix from $1,9502017-11-06 HIGH 8.8 CVE-2017-15879EPSS 7% CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before… Keystone after 4.0.0 Fix from $1,9502017-10-24 MEDIUM 6.1 CVE-2017-15878 A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us featu… Keystone 4.0.0+ Fix from $1,6002017-10-24