keystonejs records
14 published records for vendor keystonejs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 85.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-285 Improper Authorization1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-29354No exploit | An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a craftedkeystonejs · keystone · CWE-434 | Critical9.8 | — | 2.6% | May 16, 2022 |
39Monitor | CVE-2022-39382No exploit | NODE_ENV in Keystone defaults to development with esbuildkeystonejs · keystone · CWE-74 | Critical9.8 | — | 1.7% | Nov 3, 2022 |
39Monitor | CVE-2022-39322No exploit | @keystone-6/core vulnerable to field-level access-control bypass for multiselect fieldkeystonejs · keystone · CWE-285 | Critical9.8 | — | 1.2% | Oct 25, 2022 |
37Monitor | CVE-2017-15879Proof of concept | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in Keystonekeystonejs · keystone · CWE-20 | High8.8 | — | 7.2% | Oct 24, 2017 |
36Monitor | CVE-2017-16570Proof of concept | KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number Skeystonejs · keystone · CWE-352 | High8.8 | — | 2.2% | Nov 6, 2017 |
30Monitor | CVE-2015-9240No exploit | Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matchedkeystonejs · keystone · CWE-255 | High7.5 | — | 0.9% | May 29, 2018 |
25Monitor | CVE-2017-15878Proof of concept | A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contactkeystonejs · keystone · CWE-79 | Medium6.1 | — | 3.4% | Oct 24, 2017 |
25Monitor | CVE-2022-0087Proof of concept | Cross-site Scripting (XSS) - Reflected in keystonejs/keystonekeystonejs · keystone · CWE-79 | Medium6.1 | — | 2.6% | Jan 11, 2022 |
21Monitor | CVE-2021-32624No exploit | Private Field data leakkeystonejs · keystone-5 · CWE-200 | Medium5.3 | — | 0.9% | May 24, 2021 |
21Monitor | CVE-2023-40027No exploit | Conditionally missing authorization in @keystone-6/corekeystonejs · keystone · CWE-862 | Medium5.3 | — | 0.6% | Aug 15, 2023 |
19Monitor | CVE-2017-15881No exploit | Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web scrikeystonejs · keystone · CWE-79 | Medium4.8 | — | 1.2% | Oct 24, 2017 |
17Monitor | CVE-2025-46720No exploit | Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fieldskeystonejs · keystone · CWE-200 | Medium4.3 | — | 0.3% | May 5, 2025 |
17Monitor | CVE-2026-33326No exploit | @keystone-6/core: `isFilterable` bypass via `cursor` parameter in findManykeystonejs · keystone · CWE-863 | Medium4.3 | — | 0.3% | Mar 24, 2026 |
16Monitor | CVE-2023-34247No exploit | @keystone-6/auth Open Redirect vulnerabilitykeystonejs · keystone · CWE-601 | Medium4.1 | — | 0.4% | Jun 13, 2023 |
- CVE-2022-2935440Plan
An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted
CriticalCVSS 9.8No exploitEPSS 3%keystonejs · keystoneMay 16, 2022
- CVE-2022-3938239Monitor
NODE_ENV in Keystone defaults to development with esbuild
CriticalCVSS 9.8No exploitEPSS 2%keystonejs · keystoneNov 3, 2022
- CVE-2022-3932239Monitor
@keystone-6/core vulnerable to field-level access-control bypass for multiselect field
CriticalCVSS 9.8No exploitEPSS 1%keystonejs · keystoneOct 25, 2022
- CVE-2017-1587937Monitor
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in Keystone
HighCVSS 8.8Proof of conceptEPSS 7%keystonejs · keystoneOct 24, 2017
- CVE-2017-1657036Monitor
KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number S
HighCVSS 8.8Proof of conceptEPSS 2%keystonejs · keystoneNov 6, 2017
- CVE-2015-924030Monitor
Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched
HighCVSS 7.5No exploitEPSS 1%keystonejs · keystoneMay 29, 2018
- CVE-2017-1587825Monitor
A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact
MediumCVSS 6.1Proof of conceptEPSS 3%keystonejs · keystoneOct 24, 2017
- CVE-2022-008725Monitor
Cross-site Scripting (XSS) - Reflected in keystonejs/keystone
MediumCVSS 6.1Proof of conceptEPSS 3%keystonejs · keystoneJan 11, 2022
- CVE-2021-3262421Monitor
Private Field data leak
MediumCVSS 5.3No exploitEPSS 1%keystonejs · keystone-5May 24, 2021
- CVE-2023-4002721Monitor
Conditionally missing authorization in @keystone-6/core
MediumCVSS 5.3No exploitEPSS 1%keystonejs · keystoneAug 15, 2023
- CVE-2017-1588119Monitor
Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web scri
MediumCVSS 4.8No exploitEPSS 1%keystonejs · keystoneOct 24, 2017
- CVE-2025-4672017Monitor
Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields
MediumCVSS 4.3No exploitEPSS 0%keystonejs · keystoneMay 5, 2025
- CVE-2026-3332617Monitor
@keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany
MediumCVSS 4.3No exploitEPSS 0%keystonejs · keystoneMar 24, 2026
- CVE-2023-3424716Monitor
@keystone-6/auth Open Redirect vulnerability
MediumCVSS 4.1No exploitEPSS 0%keystonejs · keystoneJun 13, 2023