VYPR

Strapi

by Strapi

npm: strapi

Source repositories

CVEs (41)

  • CVE-2023-38507HigSep 15, 2023
    risk 0.41cvss 7.3epss 0.01

    Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's admin screen, but it is possible to circumvent it. Therefore, the possibility of unauthorized login by login brute force attack…

  • CVE-2026-22599HigMay 14, 2026
    risk 0.40cvss 7.2epss 0.01

    Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in the Strapi Content-Type Builder write API. An authenticated administrator could…

  • CVE-2024-34065HigJun 12, 2024
    risk 0.39cvss 7.1epss 0.01

    Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before version 4.24.2, is its possible of an unauthenticated attacker to bypass…

  • CVE-2023-37263MedSep 15, 2023
    risk 0.37cvss 6.8epss 0.01

    Strapi is the an open-source headless content management system. Prior to version 4.12.1, field level permissions are not respected in the relationship title. If an actor has relationship title and the relationship shows a field they don't have permission to see, the field will…

  • CVE-2022-0764MedFeb 26, 2022
    risk 0.37cvss 6.7epss 0.01

    Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.

  • CVE-2026-22706MedMay 14, 2026
    risk 0.35cvss 6.5epss 0.00

    Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not invalidate the user's existing refresh-token sessions by default. The refresh-token invalidation step in the users-permissions and…

  • CVE-2025-53092MedOct 16, 2025
    risk 0.35cvss 6.5epss 0.00

    Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default installations. By default, Strapi reflects the value of the Origin header back in the Access-Control-Allow-Origin response header…

  • CVE-2020-27666MedOct 22, 2020
    risk 0.35cvss 5.4epss 0.01

    Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.

  • CVE-2024-52588MedMay 29, 2025
    risk 0.32cvss 4.9epss 0.01

    Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the application fetching itself, resulting in a server side request forgery (SSRF). This issue has been patched in version 4.25.2.

  • CVE-2023-36472MedSep 15, 2023
    risk 0.31cvss 5.8epss 0.01

    Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get access to user reset password tokens if they have the configure view permissions. The `/content-manager/relations` route does not remove private fields or ensure…

  • CVE-2022-29894MedJun 13, 2022
    risk 0.31cvss 4.8epss 0.01

    Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege.

  • CVE-2026-22707MedMay 14, 2026
    risk 0.28cvss 5.4epss 0.00

    Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not enforce the administrator-configured MIME type restrictions (`plugin.upload.security.allowedTypes` and `deniedTypes`). The same…

  • CVE-2024-31217MedJun 12, 2024
    risk 0.28cvss 5.3epss 0.01

    Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process causing the server to crash without restarting, affecting either development and production environments. Usually, errors in the…

  • CVE-2025-64526MedMay 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions plugin derived its rate-limit key in part from `ctx.request.body.email`, including on routes whose body schema does not contain an…

  • CVE-2025-25298MedOct 16, 2025
    risk 0.27cvss 5.3epss 0.00

    Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum password length when using bcryptjs for password hashing. Bcryptjs ignores any bytes beyond 72, so passwords longer than 72 bytes are silently truncated. A user can…

  • CVE-2023-22894MedApr 19, 2023
    risk 0.25cvss 4.9epss 0.02

    Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from API responses. If the attacker has super…

  • CVE-2020-8123MedFeb 4, 2020
    risk 0.25cvss 4.9epss 0.01

    A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin rights can lead to arbitrary restart of the application.

  • CVE-2023-34093MedJul 25, 2023
    risk 0.24cvss 4.8epss 0.01

    Strapi is an open-source headless content management system. Prior to version 4.10.8, anyone (Strapi developers, users, plugins) can make every attribute of a Content-Type public without knowing it. The vulnerability only affects the handling of content types by Strapi, not the…

  • CVE-2024-29181LowJun 12, 2024
    risk 0.08cvss 2.3epss 0.00

    Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they…

  • CVE-2026-57997MedJun 29, 2026
    risk 0.00cvss 4.8epss 0.00

    Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 tokens alongside HS256. Attackers possessing the jwtSecret can mint tokens with non-standard HMAC…