Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Directus MEDIUM 5.4
CVE-2023-27474

Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed reset URL are vulnerable to an …

Fix: 9.23.0+
Fix from $1,600 2023-03-06
Directus MEDIUM 5.0
CVE-2022-23080

In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows …

Fix: after 9.6.0
Fix from $1,600 2022-06-22
Directus MEDIUM 6.1
CVE-2022-24814

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized JavaScript (JS) can be executed…

Fix: 9.7.0+
Fix from $1,600 2022-04-04
Directus MEDIUM 5.4
CVE-2022-22116

In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file upload in media uplo…

Fix: after 9.4.1
Fix from $1,600 2022-01-10
Directus MEDIUM 5.4
CVE-2022-22117

In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cro…

Fix: after 9.4.1
Fix from $1,600 2022-01-10
Directus HIGH 8.8
CVE-2021-29641

Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include the ability to upload a .…

Fix: 8.8.2+
Fix from $1,950 2021-04-07
Directus MEDIUM 5.3
CVE-2021-27583

In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature. NOTE: This vuln…

Fix: after 8.8.1
Fix from $1,600 2021-02-23
Directus HIGH 8.8
CVE-2021-26594

In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: Thi…

Fix: after 8.8.1
Fix from $1,950 2021-02-23
Directus HIGH 7.5
CVE-2021-26593

In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they get in response a lot of infor…

Fix: after 8.8.1
Fix from $1,950 2021-02-23
Directus MEDIUM 5.3
CVE-2021-26595

In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the …

Fix: after 8.8.1
Fix from $1,600 2021-02-23
Directus 7 Api CRITICAL 9.8
CVE-2019-13983

Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endp…

Fix: 2.2.2+
Fix from $2,300 2019-07-19
Directus 7 Api HIGH 8.8
CVE-2019-13979

In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution.

Fix: 2.2.1+
Fix from $1,950 2019-07-19
Directus 7 Api HIGH 8.8
CVE-2019-13980

In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals remote co…

Fix: after 2.3.0
Fix from $1,950 2019-07-19
Directus 7 Api HIGH 8.8
CVE-2019-13984

Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a direct link to each uploaded …

Fix: 2.3.0+
Fix from $1,950 2019-07-19
Directus 7 Api MEDIUM 5.3
CVE-2019-13981

In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory. …

Fix: after 2.3.0
Fix from $1,600 2019-07-19
Directus 7 MEDIUM 5.3
CVE-2019-13982

interfaces/markdown/input.vue in Directus 7 Application before 7.7.0 does not sanitize Markdown text before rendering a preview.

Fix: 7.7.0+
Fix from $1,600 2019-07-19
Directus CRITICAL 9.8
CVE-2018-10723

Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.

No fix yet
Fix from $2,300 2018-05-05