VYPR

Vendor CVEs

Strapi

All CVEs

41 total · sorted by risk
  • CVE-2022-27263CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.03

    An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2022-32114HigJul 13, 2022
    risk 0.57cvss 8.8epss 0.02

    An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documentation suggests that a user with the Media Library "Create (upload)" permission is supposed to be…

  • CVE-2022-30617HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.01

    An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for other admin panel users that have a relationship (e.g., created by, updated by) with content accessible to the authenticated user. For…

  • CVE-2024-37818HigJun 20, 2024
    risk 0.56cvss 8.6epss 0.01

    Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows attackers to scan for open ports or access sensitive information via a crafted GET request. NOTE: The Strapi Development Community…

  • CVE-2021-28128HigMay 6, 2021
    risk 0.53cvss 8.1epss 0.01

    In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password.

  • CVE-2022-31367HigSep 27, 2022
    risk 0.50cvss 8.8epss 0.01

    Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.

  • CVE-2023-39345HigNov 6, 2023
    risk 0.49cvss 7.6epss 0.01

    strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modify their user records. This issue has been addressed in…

  • CVE-2023-34235HigJul 25, 2023
    risk 0.49cvss 8.6epss 0.01

    Strapi is an open-source headless content management system. Prior to version 4.10.8, it is possible to leak private fields if one is using the `t(number)` prefix. Knex query allows users to change the default prefix. For example, if someone changes the prefix to be the same as…

  • CVE-2022-30618HigMay 19, 2022
    risk 0.49cvss 7.5epss 0.01

    An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for API users if content types accessible to the authenticated user contain relationships to API users (from:users-permissions). There are…

  • CVE-2024-56143HigOct 16, 2025
    risk 0.46cvss 8.2epss 0.00

    Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document service does not properly sanitize query parameters for private fields. An attacker can access private fields, including admin…

  • CVE-2023-22621HigApr 19, 2023
    risk 0.46cvss 7.2epss 0.77

    Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the Strapi admin panel can inject a crafted payload that executes code on the server into an email…

  • CVE-2026-27886HigMay 14, 2026
    risk 0.42cvss 7.5epss 0.01

    Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational fields. An unauthenticated attacker could use the `where` query parameter on…

  • CVE-2023-22893HigApr 19, 2023
    risk 0.42cvss 7.5epss 0.04

    Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could forge an ID token that is signed using the 'None' type algorithm to bypass authentication and…

  • CVE-2020-27665HigOct 22, 2020
    risk 0.42cvss 7.5epss 0.01

    In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.

  • CVE-2025-3930MedOct 16, 2025
    risk 0.41cvss epss 0.01

    Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, which allows an attacker who has stolen or intercepted the token to freely reuse it until its expiration date (which is set to 30 days by default, but can be…

  • CVE-2023-38507HigSep 15, 2023
    risk 0.41cvss 7.3epss 0.01

    Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's admin screen, but it is possible to circumvent it. Therefore, the possibility of unauthorized login by login brute force attack…

  • CVE-2026-22599HigMay 14, 2026
    risk 0.40cvss 7.2epss 0.01

    Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in the Strapi Content-Type Builder write API. An authenticated administrator could…

  • CVE-2024-34065HigJun 12, 2024
    risk 0.39cvss 7.1epss 0.01

    Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before version 4.24.2, is its possible of an unauthenticated attacker to bypass…

  • CVE-2023-37263MedSep 15, 2023
    risk 0.37cvss 6.8epss 0.01

    Strapi is the an open-source headless content management system. Prior to version 4.12.1, field level permissions are not respected in the relationship title. If an actor has relationship title and the relationship shows a field they don't have permission to see, the field will…

  • CVE-2022-0764MedFeb 26, 2022
    risk 0.37cvss 6.7epss 0.01

    Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.

  • CVE-2026-22706MedMay 14, 2026
    risk 0.35cvss 6.5epss 0.00

    Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not invalidate the user's existing refresh-token sessions by default. The refresh-token invalidation step in the users-permissions and…

  • CVE-2025-53092MedOct 16, 2025
    risk 0.35cvss 6.5epss 0.00

    Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default installations. By default, Strapi reflects the value of the Origin header back in the Access-Control-Allow-Origin response header…

  • CVE-2024-52588MedMay 29, 2025
    risk 0.32cvss 4.9epss 0.00

    Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the application fetching itself, resulting in a server side request forgery (SSRF). This issue has been patched in version 4.25.2.

  • CVE-2023-36472MedSep 15, 2023
    risk 0.31cvss 5.8epss 0.01

    Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get access to user reset password tokens if they have the configure view permissions. The `/content-manager/relations` route does not remove private fields or ensure…

  • CVE-2022-29894MedJun 13, 2022
    risk 0.31cvss 4.8epss 0.01

    Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege.

  • CVE-2026-22707MedMay 14, 2026
    risk 0.28cvss 5.4epss 0.00

    Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not enforce the administrator-configured MIME type restrictions (`plugin.upload.security.allowedTypes` and `deniedTypes`). The same…

  • CVE-2024-31217MedJun 12, 2024
    risk 0.28cvss 5.3epss 0.01

    Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process causing the server to crash without restarting, affecting either development and production environments. Usually, errors in the…

  • CVE-2025-64526MedMay 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions plugin derived its rate-limit key in part from `ctx.request.body.email`, including on routes whose body schema does not contain an…

  • CVE-2025-25298MedOct 16, 2025
    risk 0.27cvss 5.3epss 0.00

    Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum password length when using bcryptjs for password hashing. Bcryptjs ignores any bytes beyond 72, so passwords longer than 72 bytes are silently truncated. A user can…

  • CVE-2023-48218MedNov 20, 2023
    risk 0.27cvss 5.3epss 0.01

    The Strapi Protected Populate Plugin protects `get` endpoints from revealing too much information. Prior to version 1.3.4, users were able to bypass the field level security. Users who tried to populate something that they didn't have access to could populate those fields…

  • CVE-2023-22894MedApr 19, 2023
    risk 0.25cvss 4.9epss 0.02

    Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from API responses. If the attacker has super…

  • CVE-2020-8123MedFeb 4, 2020
    risk 0.25cvss 4.9epss 0.01

    A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin rights can lead to arbitrary restart of the application.

  • CVE-2023-34093MedJul 25, 2023
    risk 0.24cvss 4.8epss 0.01

    Strapi is an open-source headless content management system. Prior to version 4.10.8, anyone (Strapi developers, users, plugins) can make every attribute of a Content-Type public without knowing it. The vulnerability only affects the handling of content types by Strapi, not the…

  • CVE-2019-18818CriNov 7, 2019
    risk 0.11cvss 9.8epss 0.98

    strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.

  • CVE-2024-29181LowJun 12, 2024
    risk 0.08cvss 2.3epss 0.00

    Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they…

  • CVE-2019-19609HigDec 5, 2019
    risk 0.07cvss 7.2epss 0.54

    The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa…

  • CVE-2026-57997MedJun 29, 2026
    risk 0.00cvss 4.8epss 0.00

    Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 tokens alongside HS256. Attackers possessing the jwtSecret can mint tokens with non-standard HMAC…

  • CVE-2021-46440HigMay 3, 2022
    risk 0.00cvss 7.5epss 0.03

    Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, get the victim's cookie, perform a base64 decode on the victim's cookie, and obtain a cleartext…

  • CVE-2020-27666MedOct 22, 2020
    risk 0.00cvss 5.4epss 0.01

    Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.

  • CVE-2020-27664CriOct 22, 2020
    risk 0.00cvss 9.8epss 0.02

    admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.

  • CVE-2020-13961MedJun 19, 2020
    risk 0.00cvss 6.5epss 0.02

    Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global variable without any sanitation. By sending a specially crafted request, an attacker could exploit this vulnerability to update the email…