VYPR
Vendor

Strapi

Products
3
CVEs
41
Across products
42
Status
Private

Products

3

Recent CVEs

41
View all 41 CVEs →
  • CVE-2022-27263CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.03

    An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2022-32114HigJul 13, 2022
    risk 0.57cvss 8.8epss 0.02

    An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documentation suggests that a user with the Media Library "Create (upload)" permission is supposed to be…

  • CVE-2022-30617HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.01

    An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for other admin panel users that have a relationship (e.g., created by, updated by) with content accessible to the authenticated user. For…

  • CVE-2024-37818HigJun 20, 2024
    risk 0.56cvss 8.6epss 0.01

    Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows attackers to scan for open ports or access sensitive information via a crafted GET request. NOTE: The Strapi Development Community…

  • CVE-2021-28128HigMay 6, 2021
    risk 0.53cvss 8.1epss 0.01

    In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password.

  • CVE-2022-31367HigSep 27, 2022
    risk 0.50cvss 8.8epss 0.01

    Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.

  • CVE-2023-39345HigNov 6, 2023
    risk 0.49cvss 7.6epss 0.01

    strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modify their user records. This issue has been addressed in…

  • CVE-2023-34235HigJul 25, 2023
    risk 0.49cvss 8.6epss 0.01

    Strapi is an open-source headless content management system. Prior to version 4.10.8, it is possible to leak private fields if one is using the `t(number)` prefix. Knex query allows users to change the default prefix. For example, if someone changes the prefix to be the same as…

  • CVE-2022-30618HigMay 19, 2022
    risk 0.49cvss 7.5epss 0.01

    An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for API users if content types accessible to the authenticated user contain relationships to API users (from:users-permissions). There are…

  • CVE-2024-56143HigOct 16, 2025
    risk 0.46cvss 8.2epss 0.00

    Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document service does not properly sanitize query parameters for private fields. An attacker can access private fields, including admin…

  • CVE-2023-22621HigApr 19, 2023
    risk 0.46cvss 7.2epss 0.77

    Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the Strapi admin panel can inject a crafted payload that executes code on the server into an email…

  • CVE-2026-27886HigMay 14, 2026
    risk 0.42cvss 7.5epss 0.01

    Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational fields. An unauthenticated attacker could use the `where` query parameter on…

  • CVE-2023-22893HigApr 19, 2023
    risk 0.42cvss 7.5epss 0.04

    Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could forge an ID token that is signed using the 'None' type algorithm to bypass authentication and…

  • CVE-2020-27665HigOct 22, 2020
    risk 0.42cvss 7.5epss 0.01

    In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.

  • CVE-2025-3930MedOct 16, 2025
    risk 0.41cvss epss 0.01

    Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, which allows an attacker who has stolen or intercepted the token to freely reuse it until its expiration date (which is set to 30 days by default, but can be…

  • CVE-2023-38507HigSep 15, 2023
    risk 0.41cvss 7.3epss 0.01

    Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's admin screen, but it is possible to circumvent it. Therefore, the possibility of unauthorized login by login brute force attack…

  • CVE-2026-22599HigMay 14, 2026
    risk 0.40cvss 7.2epss 0.01

    Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in the Strapi Content-Type Builder write API. An authenticated administrator could…

  • CVE-2024-34065HigJun 12, 2024
    risk 0.39cvss 7.1epss 0.01

    Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before version 4.24.2, is its possible of an unauthenticated attacker to bypass…

  • CVE-2023-37263MedSep 15, 2023
    risk 0.37cvss 6.8epss 0.01

    Strapi is the an open-source headless content management system. Prior to version 4.12.1, field level permissions are not respected in the relationship title. If an actor has relationship title and the relationship shows a field they don't have permission to see, the field will…

  • CVE-2022-0764MedFeb 26, 2022
    risk 0.37cvss 6.7epss 0.01

    Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.