Skip to main content

Vendor archive

strapi CVEs

Beta · best-effort

40 CVEs tagged to vendor strapi5 Critical, 16 High, 17 Medium, 2 Low, 0 Unrated.

CVE-2022-32114

Published Jul 13, 2022

An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documen…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29894

Published Jun 13, 2022

Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By exploiting this vulnerability, an arbitrary script may be execut…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30618

Published May 19, 2022

An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for API users if content types accessible…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-30617

Published May 19, 2022

An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for other admin panel users that have a r…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-46440

Published May 3, 2022

Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, g…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27263

Published Apr 12, 2022

An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-0764

Published Feb 26, 2022

Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28128

Published May 6, 2021

In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use t…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27666

Published Oct 22, 2020

Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27665

Published Oct 22, 2020

In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27664

Published Oct 22, 2020

admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-13961

Published Jun 19, 2020

Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global variable without any sanitation. By sendin…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8123

Published Feb 4, 2020

A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin rights can lead to arbitrary restart of the application.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19609

Published Dec 5, 2019

The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18818

Published Nov 7, 2019

strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 26-40 of 40 CVEsPage 2 of 2