VYPR

Strapi

by Strapi

npm: strapi

Source repositories

CVEs (40)

  • CVE-2026-22706MedMay 14, 2026
    risk 0.35cvss 6.5epss 0.00

    Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not invalidate the user's existing refresh-token sessions by default. The refresh-token invalidation step in the users-permissions and…

  • CVE-2025-53092MedOct 16, 2025
    risk 0.35cvss 6.5epss 0.00

    Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default installations. By default, Strapi reflects the value of the Origin header back in the Access-Control-Allow-Origin response header…

  • CVE-2024-52588MedMay 29, 2025
    risk 0.32cvss 4.9epss 0.00

    Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the application fetching itself, resulting in a server side request forgery (SSRF). This issue has been patched in version 4.25.2.

  • CVE-2023-36472MedSep 15, 2023
    risk 0.31cvss 5.8epss 0.01

    Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get access to user reset password tokens if they have the configure view permissions. The `/content-manager/relations` route does not remove private fields or ensure…

  • CVE-2022-29894MedJun 13, 2022
    risk 0.31cvss 4.8epss 0.01

    Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege.

  • CVE-2026-22707MedMay 14, 2026
    risk 0.28cvss 5.4epss 0.00

    Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not enforce the administrator-configured MIME type restrictions (`plugin.upload.security.allowedTypes` and `deniedTypes`). The same…

  • CVE-2024-31217MedJun 12, 2024
    risk 0.28cvss 5.3epss 0.01

    Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process causing the server to crash without restarting, affecting either development and production environments. Usually, errors in the…

  • CVE-2025-64526MedMay 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions plugin derived its rate-limit key in part from `ctx.request.body.email`, including on routes whose body schema does not contain an…

  • CVE-2025-25298MedOct 16, 2025
    risk 0.27cvss 5.3epss 0.00

    Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum password length when using bcryptjs for password hashing. Bcryptjs ignores any bytes beyond 72, so passwords longer than 72 bytes are silently truncated. A user can…

  • CVE-2023-22894MedApr 19, 2023
    risk 0.25cvss 4.9epss 0.02

    Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from API responses. If the attacker has super…

  • CVE-2020-8123MedFeb 4, 2020
    risk 0.25cvss 4.9epss 0.01

    A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin rights can lead to arbitrary restart of the application.

  • CVE-2023-34093MedJul 25, 2023
    risk 0.24cvss 4.8epss 0.01

    Strapi is an open-source headless content management system. Prior to version 4.10.8, anyone (Strapi developers, users, plugins) can make every attribute of a Content-Type public without knowing it. The vulnerability only affects the handling of content types by Strapi, not the…

  • CVE-2019-18818CriNov 7, 2019
    risk 0.11cvss 9.8epss 0.98

    strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.

  • CVE-2024-29181LowJun 12, 2024
    risk 0.08cvss 2.3epss 0.00

    Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they…

  • CVE-2019-19609HigDec 5, 2019
    risk 0.07cvss 7.2epss 0.54

    The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa…

  • CVE-2026-57997MedJun 29, 2026
    risk 0.00cvss 4.8epss 0.00

    Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 tokens alongside HS256. Attackers possessing the jwtSecret can mint tokens with non-standard HMAC…

  • CVE-2021-46440HigMay 3, 2022
    risk 0.00cvss 7.5epss 0.03

    Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, get the victim's cookie, perform a base64 decode on the victim's cookie, and obtain a cleartext…

  • CVE-2020-27666MedOct 22, 2020
    risk 0.00cvss 5.4epss 0.01

    Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.

  • CVE-2020-27664CriOct 22, 2020
    risk 0.00cvss 9.8epss 0.02

    admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.

  • CVE-2020-13961MedJun 19, 2020
    risk 0.00cvss 6.5epss 0.02

    Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global variable without any sanitation. By sending a specially crafted request, an attacker could exploit this vulnerability to update the email…

Page 2 of 2