Skip to content
Noroxi

strapi records

40 published records for vendor strapi.

All records

40 records
  • CVE-2019-18818
    68This week

    strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-p

    CriticalCVSS 9.8WeaponizedEPSS 98%

    strapi · strapiNov 7, 2019

  • Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the serve

    HighCVSS 7.2Proof of conceptEPSS 71%

    strapi · strapiApr 19, 2023

  • The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Adm

    HighCVSS 7.2Proof of conceptEPSS 54%

    strapi · strapiDec 5, 2019

  • An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted f

    CriticalCVSS 9.8No exploitEPSS 3%

    strapi · strapiApr 12, 2022

  • admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.

    CriticalCVSS 9.8No exploitEPSS 2%

    strapi · strapiOct 22, 2020

  • Strapi Improper Rate Limiting vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    strapi · strapiSep 15, 2023

  • Strapi may leak sensitive data via relational filtering due to lack of query sanitization

    CriticalCVSS 9.2Proof of conceptEPSS 3%

    strapi · strapiMay 14, 2026

  • Strapi Vulnerable to SQL Injection in Content Type Builder

    CriticalCVSS 9.3Proof of conceptEPSS 1%

    strapi · strapiMay 14, 2026

  • An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a craf

    HighCVSS 8.8Proof of conceptEPSS 2%

    strapi · strapiJul 13, 2022

  • Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.

    HighCVSS 8.8No exploitEPSS 2%

    strapi · strapiSep 27, 2022

  • An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo

    HighCVSS 8.8No exploitEPSS 1%

    strapi · strapiMay 19, 2022

  • Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image.

    HighCVSS 8.6No exploitEPSS 1%

    strapi · strapiJun 20, 2024

  • In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password.

    HighCVSS 8.1No exploitEPSS 1%

    strapi · strapiMay 6, 2021

  • @strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass

    HighCVSS 8.1No exploitEPSS 1%

    strapi · strapiJun 12, 2024

  • Strapi Allows Unauthorized Access to Private Fields via parms.lookup

    HighCVSS 8.2No exploitEPSS 0%

    strapi · strapiOct 16, 2025

  • Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for au

    HighCVSS 7.5Proof of conceptEPSS 4%

    strapi · strapiApr 19, 2023

  • Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attack

    HighCVSS 7.5No exploitEPSS 3%

    strapi · strapiMay 3, 2022

  • In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.

    HighCVSS 7.5No exploitEPSS 1%

    strapi · strapiOct 22, 2020

  • Leaking sensitive user information still possible by filtering on private with prefix fields

    HighCVSS 7.5No exploitEPSS 1%

    strapi · strapiJul 25, 2023

  • An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo

    HighCVSS 7.5No exploitEPSS 1%

    strapi · strapiMay 19, 2022

  • Unauthorized Access to Private Fields in User Registration API in strapi

    HighCVSS 7.5No exploitEPSS 1%

    strapi · strapiNov 6, 2023

  • Strapi allows Server-Side Request Forgery in Webhook function

    HighCVSS 7.5No exploitEPSS 1%

    strapi · strapiMay 29, 2025

  • Strapi allows actors to make all attributes on a content-type public without noticing it

    HighCVSS 7.1No exploitEPSS 1%

    strapi · strapiJul 25, 2023

  • Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying

    MediumCVSS 6.9No exploitEPSS 0%

    strapi · strapiMay 14, 2026

  • Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global var

    MediumCVSS 6.5No exploitEPSS 2%

    strapi · strapiJun 19, 2020