Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Strapi MEDIUM 5.4
CVE-2026-57997

Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing …

Fix: 5.7.0+
Fix from $1,600 2026-06-29
Strapi HIGH 7.5
CVE-2026-27886

Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize quer…

Fix: 5.37.0+
Fix from $1,950 2026-05-14
Strapi MEDIUM 6.5
CVE-2026-22706

Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not inva…

Fix: 5.33.3+
Fix from $1,600 2026-05-14
Strapi MEDIUM 5.4
CVE-2026-22707

Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not en…

Fix: 5.33.3+
Fix from $1,600 2026-05-14
Strapi HIGH 7.2
CVE-2026-22599

Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a d…

Fix: 4.26.1 / 5.33.2+
Fix from $1,950 2026-05-14
Strapi MEDIUM 5.3
CVE-2025-64526

Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions p…

Fix: 5.45.0+
Fix from $1,600 2026-05-14
Strapi MEDIUM 6.5
CVE-2025-53092

Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default…

Fix: 5.20.0+
Fix from $1,600 2025-10-16
Strapi MEDIUM 5.3
CVE-2025-25298

Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum password length when using bcryptjs …

Fix: 5.10.3+
Fix from $1,600 2025-10-16
Strapi HIGH 8.2
CVE-2024-56143

Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document ser…

Fix: 5.5.2+
Fix from $1,950 2025-10-16
Strapi HIGH 7.5
CVE-2024-52588

Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the applic…

Fix: 4.25.2+
Fix from $1,950 2025-05-29
Strapi HIGH 8.6
CVE-2024-37818

Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows att…

No fix yet
Fix from $1,950 2024-06-20
Strapi HIGH 8.1
CVE-2024-34065

Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query paramet…

Fix: 4.24.2+
Fix from $1,950 2024-06-12
Strapi MEDIUM 6.5
CVE-2024-31217

Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process…

Fix: 4.22.0+
Fix from $1,600 2024-06-12
Protected Populate MEDIUM 5.3
CVE-2023-48218

The Strapi Protected Populate Plugin protects `get` endpoints from revealing too much information. Prior to version 1.3.4, users were able to bypass …

Fix: 1.3.4+
Fix from $1,600 2023-11-20
Strapi HIGH 7.5
CVE-2023-39345

strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user regis…

Fix: 4.13.1+
Fix from $1,950 2023-11-06
Strapi CRITICAL 9.8
CVE-2023-38507

Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's adm…

Fix: 4.12.1+
Fix from $2,300 2023-09-15
Strapi MEDIUM 5.7
CVE-2023-36472

Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get access to user reset password tok…

Fix: 4.11.7+
Fix from $1,600 2023-09-15
Strapi HIGH 7.5
CVE-2023-34235

Strapi is an open-source headless content management system. Prior to version 4.10.8, it is possible to leak private fields if one is using the `t(nu…

Fix: 4.10.8+
Fix from $1,950 2023-07-25
Strapi HIGH 7.1
CVE-2023-34093

Strapi is an open-source headless content management system. Prior to version 4.10.8, anyone (Strapi developers, users, plugins) can make every attri…

Fix: 4.10.8+
Fix from $1,950 2023-07-25
Strapi HIGH 7.5
CVE-2023-22893

Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authenticat…

Fix: 4.6.0+
Fix from $1,950 2023-04-19
Strapi HIGH 7.2
CVE-2023-22621EPSS 77%

Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remo…

Fix: 4.5.6+
Fix from $1,950 2023-04-19
Strapi HIGH 8.8
CVE-2022-31367

Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.

Fix: 3.6.10 / 4.1.10+
Fix from $1,950 2022-09-27
Strapi HIGH 8.8
CVE-2022-32114

An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF f…

No fix yet
Fix from $1,950 2022-07-13
Strapi HIGH 8.8
CVE-2022-30617

An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for other a…

Fix: 3.6.10+
Fix from $1,950 2022-05-19
Strapi HIGH 7.5
CVE-2022-30618

An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for API use…

Fix: 3.6.10 / 4.1.10+
Fix from $1,950 2022-05-19
Strapi HIGH 7.5
CVE-2021-46440

Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to acc…

Fix: 3.6.9 / 4.1.5+
Fix from $1,950 2022-05-03
Strapi CRITICAL 9.8
CVE-2022-27263

An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.

No fix yet
Fix from $2,300 2022-04-12
Strapi MEDIUM 6.7
CVE-2022-0764

Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.

Fix: 4.1.0+
Fix from $1,600 2022-02-26
Strapi HIGH 8.1
CVE-2021-28128

In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains acces…

Fix: after 3.6.0
Fix from $1,950 2021-05-06
Strapi CRITICAL 9.8
CVE-2020-27664

admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.

Fix: 3.2.5+
Fix from $2,300 2020-10-22