Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-57997 Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing … Strapi 5.7.0+ Fix from $1,6002026-06-29 HIGH 7.5 CVE-2026-27886 Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize quer… Strapi 5.37.0+ Fix from $1,9502026-05-14 MEDIUM 6.5 CVE-2026-22706 Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not inva… Strapi 5.33.3+ Fix from $1,6002026-05-14 MEDIUM 5.4 CVE-2026-22707 Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not en… Strapi 5.33.3+ Fix from $1,6002026-05-14 HIGH 7.2 CVE-2026-22599 Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a d… Strapi 4.26.1 / 5.33.2+ Fix from $1,9502026-05-14 MEDIUM 5.3 CVE-2025-64526 Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions p… Strapi 5.45.0+ Fix from $1,6002026-05-14 MEDIUM 6.5 CVE-2025-53092 Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default… Strapi 5.20.0+ Fix from $1,6002025-10-16 MEDIUM 5.3 CVE-2025-25298 Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum password length when using bcryptjs … Strapi 5.10.3+ Fix from $1,6002025-10-16 HIGH 8.2 CVE-2024-56143 Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document ser… Strapi 5.5.2+ Fix from $1,9502025-10-16 HIGH 7.5 CVE-2024-52588 Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the applic… Strapi 4.25.2+ Fix from $1,9502025-05-29 HIGH 8.6 CVE-2024-37818 Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows att… Strapi No fix yet Fix from $1,9502024-06-20 HIGH 8.1 CVE-2024-34065 Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query paramet… Strapi 4.24.2+ Fix from $1,9502024-06-12 MEDIUM 6.5 CVE-2024-31217 Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process… Strapi 4.22.0+ Fix from $1,6002024-06-12 MEDIUM 5.3 CVE-2023-48218 The Strapi Protected Populate Plugin protects `get` endpoints from revealing too much information. Prior to version 1.3.4, users were able to bypass … Protected Populate 1.3.4+ Fix from $1,6002023-11-20 HIGH 7.5 CVE-2023-39345 strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user regis… Strapi 4.13.1+ Fix from $1,9502023-11-06 CRITICAL 9.8 CVE-2023-38507 Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's adm… Strapi 4.12.1+ Fix from $2,3002023-09-15 MEDIUM 5.7 CVE-2023-36472 Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get access to user reset password tok… Strapi 4.11.7+ Fix from $1,6002023-09-15 HIGH 7.5 CVE-2023-34235 Strapi is an open-source headless content management system. Prior to version 4.10.8, it is possible to leak private fields if one is using the `t(nu… Strapi 4.10.8+ Fix from $1,9502023-07-25 HIGH 7.1 CVE-2023-34093 Strapi is an open-source headless content management system. Prior to version 4.10.8, anyone (Strapi developers, users, plugins) can make every attri… Strapi 4.10.8+ Fix from $1,9502023-07-25 HIGH 7.5 CVE-2023-22893 Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authenticat… Strapi 4.6.0+ Fix from $1,9502023-04-19 HIGH 7.2 CVE-2023-22621EPSS 77% Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remo… Strapi 4.5.6+ Fix from $1,9502023-04-19 HIGH 8.8 CVE-2022-31367 Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses. Strapi 3.6.10 / 4.1.10+ Fix from $1,9502022-09-27 HIGH 8.8 CVE-2022-32114 An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF f… Strapi No fix yet Fix from $1,9502022-07-13 HIGH 8.8 CVE-2022-30617 An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for other a… Strapi 3.6.10+ Fix from $1,9502022-05-19 HIGH 7.5 CVE-2022-30618 An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for API use… Strapi 3.6.10 / 4.1.10+ Fix from $1,9502022-05-19 HIGH 7.5 CVE-2021-46440 Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to acc… Strapi 3.6.9 / 4.1.5+ Fix from $1,9502022-05-03 CRITICAL 9.8 CVE-2022-27263 An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file. Strapi No fix yet Fix from $2,3002022-04-12 MEDIUM 6.7 CVE-2022-0764 Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0. Strapi 4.1.0+ Fix from $1,6002022-02-26 HIGH 8.1 CVE-2021-28128 In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains acces… Strapi after 3.6.0 Fix from $1,9502021-05-06 CRITICAL 9.8 CVE-2020-27664 admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality. Strapi 3.2.5+ Fix from $2,3002020-10-22