Skip to content
Noroxi

keystonejs records

14 published records for vendor keystonejs.

All records

14 records
  • An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted

    CriticalCVSS 9.8No exploitEPSS 3%

    keystonejs · keystoneMay 16, 2022

  • NODE_ENV in Keystone defaults to development with esbuild

    CriticalCVSS 9.8No exploitEPSS 2%

    keystonejs · keystoneNov 3, 2022

  • @keystone-6/core vulnerable to field-level access-control bypass for multiselect field

    CriticalCVSS 9.8No exploitEPSS 1%

    keystonejs · keystoneOct 25, 2022

  • CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in Keystone

    HighCVSS 8.8Proof of conceptEPSS 7%

    keystonejs · keystoneOct 24, 2017

  • KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number S

    HighCVSS 8.8Proof of conceptEPSS 2%

    keystonejs · keystoneNov 6, 2017

  • CVE-2015-9240
    30Monitor

    Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched

    HighCVSS 7.5No exploitEPSS 1%

    keystonejs · keystoneMay 29, 2018

  • A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact

    MediumCVSS 6.1Proof of conceptEPSS 3%

    keystonejs · keystoneOct 24, 2017

  • CVE-2022-0087
    25Monitor

    Cross-site Scripting (XSS) - Reflected in keystonejs/keystone

    MediumCVSS 6.1Proof of conceptEPSS 3%

    keystonejs · keystoneJan 11, 2022

  • Private Field data leak

    MediumCVSS 5.3No exploitEPSS 1%

    keystonejs · keystone-5May 24, 2021

  • Conditionally missing authorization in @keystone-6/core

    MediumCVSS 5.3No exploitEPSS 1%

    keystonejs · keystoneAug 15, 2023

  • Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web scri

    MediumCVSS 4.8No exploitEPSS 1%

    keystonejs · keystoneOct 24, 2017

  • Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields

    MediumCVSS 4.3No exploitEPSS 0%

    keystonejs · keystoneMay 5, 2025

  • @keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany

    MediumCVSS 4.3No exploitEPSS 0%

    keystonejs · keystoneMar 24, 2026

  • @keystone-6/auth Open Redirect vulnerability

    MediumCVSS 4.1No exploitEPSS 0%

    keystonejs · keystoneJun 13, 2023