Skip to main content

Vendor/product archive

strapi / strapi CVEs

Beta · best-effort

39 CVEs tagged to strapi / strapi5 Critical, 16 High, 16 Medium, 2 Low, 0 Unrated.

CVE-2026-57997

Published Jun 29, 2026

Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-27886

Published May 14, 2026

Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering co…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22707

Published May 14, 2026

Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not enforce the administrator-config…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22706

Published May 14, 2026

Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not invalidate the user's existing ref…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22599

Published May 14, 2026

Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulner…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-64526

Published May 14, 2026

Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions plugin derived its rate-limit k…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53092

Published Oct 16, 2025

Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default installations. By default, St…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25298

Published Oct 16, 2025

Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum password length when using bcryptjs for password hashing. Bcryptjs…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56143

Published Oct 16, 2025

Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document service does not properly sanitiz…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52588

Published May 29, 2025

Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the application fetching itself, resulti…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37818

Published Jun 20, 2024

Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows attackers to scan for open ports…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34065

Published Jun 12, 2024

Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-p…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31217

Published Jun 12, 2024

Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process causing the server to crash w…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29181

Published Jun 12, 2024

Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another co…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-39345

Published Nov 6, 2023

strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such mali…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38507

Published Sep 15, 2023

Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's admin screen, but it is possible…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37263

Published Sep 15, 2023

Strapi is the an open-source headless content management system. Prior to version 4.12.1, field level permissions are not respected in the relationship title. If an actor has rela…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36472

Published Sep 15, 2023

Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get access to user reset password tokens if they have the configure…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34235

Published Jul 25, 2023

Strapi is an open-source headless content management system. Prior to version 4.10.8, it is possible to leak private fields if one is using the `t(number)` prefix. Knex query allo…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34093

Published Jul 25, 2023

Strapi is an open-source headless content management system. Prior to version 4.10.8, anyone (Strapi developers, users, plugins) can make every attribute of a Content-Type public…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22894

Published Apr 19, 2023

Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22893

Published Apr 19, 2023

Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22621

Published Apr 19, 2023

Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31367

Published Sep 27, 2022

Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32114

Published Jul 13, 2022

An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documen…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 39 CVEsPage 1 of 2