Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
Strapi
HIGH 7.5
CVE-2020-27665
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
Fix: 3.2.5+
Fix from $1,950
2020-10-22
Strapi
MEDIUM 5.4
CVE-2020-27666
Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.
Fix: 3.2.5+
Fix from $1,600
2020-10-22
Strapi
MEDIUM 6.5
CVE-2020-13961
Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global variable wit…
Fix: 3.0.2+
Fix from $1,600
2020-06-19
Strapi
HIGH 7.2
CVE-2019-19609EPSS 54%
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel,…
Fix: after 1.6.4
Fix from $1,950
2019-12-05
Strapi
CRITICAL 9.8
CVE-2019-18818EPSS 98%
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permission…
Fix: after 1.6.4
Fix from $2,300
2019-11-07