strapi records
40 published records for vendor strapi.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 2.5%
- Pre-auth RCE
- 1
- With a fix record
- 87.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-287 Improper Authentication2
- CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer2
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password2
The weakness classes this vendor ships most often: where to look.
CWEAll records
40 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
68This week | CVE-2019-18818Weaponized | strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-pstrapi · strapi · CWE-640 | Critical9.8 | — | 97.6% | Nov 7, 2019 |
49Plan | CVE-2023-22621Proof of concept | Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the servestrapi · strapi · CWE-74 | High7.2 | — | 70.6% | Apr 19, 2023 |
44Plan | CVE-2019-19609Proof of concept | The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admstrapi · strapi · CWE-78 | High7.2 | — | 54.1% | Dec 5, 2019 |
40Plan | CVE-2022-27263No exploit | An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted fstrapi · strapi · CWE-434 | Critical9.8 | — | 3.2% | Apr 12, 2022 |
40Plan | CVE-2020-27664No exploit | admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.strapi · strapi | Critical9.8 | — | 2.3% | Oct 22, 2020 |
39Monitor | CVE-2023-38507No exploit | Strapi Improper Rate Limiting vulnerabilitystrapi · strapi · CWE-770 | Critical9.8 | — | 1.0% | Sep 15, 2023 |
37Monitor | CVE-2026-27886Proof of concept | Strapi may leak sensitive data via relational filtering due to lack of query sanitizationstrapi · strapi · CWE-22 | Critical9.2 | — | 2.5% | May 14, 2026 |
37Monitor | CVE-2026-22599Proof of concept | Strapi Vulnerable to SQL Injection in Content Type Builderstrapi · strapi · CWE-89 | Critical9.3 | — | 1.2% | May 14, 2026 |
36Monitor | CVE-2022-32114Proof of concept | An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafstrapi · strapi · CWE-434 | High8.8 | — | 2.0% | Jul 13, 2022 |
36Monitor | CVE-2022-31367No exploit | Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.strapi · strapi · CWE-89 | High8.8 | — | 1.7% | Sep 27, 2022 |
35Monitor | CVE-2022-30617No exploit | An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fostrapi · strapi · CWE-212 | High8.8 | — | 1.5% | May 19, 2022 |
34Monitor | CVE-2024-37818No exploit | Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image.strapi · strapi · CWE-918 | High8.6 | — | 0.6% | Jun 20, 2024 |
32Monitor | CVE-2021-28128No exploit | In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password.strapi · strapi · CWE-640 | High8.1 | — | 1.3% | May 6, 2021 |
32Monitor | CVE-2024-34065No exploit | @strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypassstrapi · strapi · CWE-294 | High8.1 | — | 0.7% | Jun 12, 2024 |
32Monitor | CVE-2024-56143No exploit | Strapi Allows Unauthorized Access to Private Fields via parms.lookupstrapi · strapi · CWE-639 | High8.2 | — | 0.4% | Oct 16, 2025 |
31Monitor | CVE-2023-22893Proof of concept | Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for austrapi · strapi · CWE-287 | High7.5 | — | 4.1% | Apr 19, 2023 |
31Monitor | CVE-2021-46440No exploit | Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attackstrapi · strapi · CWE-522 | High7.5 | — | 2.9% | May 3, 2022 |
30Monitor | CVE-2020-27665No exploit | In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.strapi · strapi · CWE-276 | High7.5 | — | 1.2% | Oct 22, 2020 |
30Monitor | CVE-2023-34235No exploit | Leaking sensitive user information still possible by filtering on private with prefix fieldsstrapi · strapi · CWE-200 | High7.5 | — | 1.1% | Jul 25, 2023 |
30Monitor | CVE-2022-30618No exploit | An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fostrapi · strapi · CWE-212 | High7.5 | — | 0.9% | May 19, 2022 |
30Monitor | CVE-2023-39345No exploit | Unauthorized Access to Private Fields in User Registration API in strapistrapi · strapi · CWE-287 | High7.5 | — | 0.6% | Nov 6, 2023 |
30Monitor | CVE-2024-52588No exploit | Strapi allows Server-Side Request Forgery in Webhook functionstrapi · strapi · CWE-918 | High7.5 | — | 0.6% | May 29, 2025 |
28Monitor | CVE-2023-34093No exploit | Strapi allows actors to make all attributes on a content-type public without noticing itstrapi · strapi · CWE-200 | High7.1 | — | 0.7% | Jul 25, 2023 |
27Monitor | CVE-2025-64526No exploit | Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keyingstrapi · strapi · CWE-307 | Medium6.9 | — | 0.5% | May 14, 2026 |
26Monitor | CVE-2020-13961No exploit | Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global varstrapi · strapi · CWE-20 | Medium6.5 | — | 1.7% | Jun 19, 2020 |
- CVE-2019-1881868This week
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-p
CriticalCVSS 9.8WeaponizedEPSS 98%strapi · strapiNov 7, 2019
- CVE-2023-2262149Plan
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the serve
HighCVSS 7.2Proof of conceptEPSS 71%strapi · strapiApr 19, 2023
- CVE-2019-1960944Plan
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Adm
HighCVSS 7.2Proof of conceptEPSS 54%strapi · strapiDec 5, 2019
- CVE-2022-2726340Plan
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted f
CriticalCVSS 9.8No exploitEPSS 3%strapi · strapiApr 12, 2022
- CVE-2020-2766440Plan
admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.
CriticalCVSS 9.8No exploitEPSS 2%strapi · strapiOct 22, 2020
- CVE-2023-3850739Monitor
Strapi Improper Rate Limiting vulnerability
CriticalCVSS 9.8No exploitEPSS 1%strapi · strapiSep 15, 2023
- CVE-2026-2788637Monitor
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
CriticalCVSS 9.2Proof of conceptEPSS 3%strapi · strapiMay 14, 2026
- CVE-2026-2259937Monitor
Strapi Vulnerable to SQL Injection in Content Type Builder
CriticalCVSS 9.3Proof of conceptEPSS 1%strapi · strapiMay 14, 2026
- CVE-2022-3211436Monitor
An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a craf
HighCVSS 8.8Proof of conceptEPSS 2%strapi · strapiJul 13, 2022
- CVE-2022-3136736Monitor
Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.
HighCVSS 8.8No exploitEPSS 2%strapi · strapiSep 27, 2022
- CVE-2022-3061735Monitor
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo
HighCVSS 8.8No exploitEPSS 1%strapi · strapiMay 19, 2022
- CVE-2024-3781834Monitor
Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image.
HighCVSS 8.6No exploitEPSS 1%strapi · strapiJun 20, 2024
- CVE-2021-2812832Monitor
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password.
HighCVSS 8.1No exploitEPSS 1%strapi · strapiMay 6, 2021
- CVE-2024-3406532Monitor
@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass
HighCVSS 8.1No exploitEPSS 1%strapi · strapiJun 12, 2024
- CVE-2024-5614332Monitor
Strapi Allows Unauthorized Access to Private Fields via parms.lookup
HighCVSS 8.2No exploitEPSS 0%strapi · strapiOct 16, 2025
- CVE-2023-2289331Monitor
Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for au
HighCVSS 7.5Proof of conceptEPSS 4%strapi · strapiApr 19, 2023
- CVE-2021-4644031Monitor
Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attack
HighCVSS 7.5No exploitEPSS 3%strapi · strapiMay 3, 2022
- CVE-2020-2766530Monitor
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
HighCVSS 7.5No exploitEPSS 1%strapi · strapiOct 22, 2020
- CVE-2023-3423530Monitor
Leaking sensitive user information still possible by filtering on private with prefix fields
HighCVSS 7.5No exploitEPSS 1%strapi · strapiJul 25, 2023
- CVE-2022-3061830Monitor
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo
HighCVSS 7.5No exploitEPSS 1%strapi · strapiMay 19, 2022
- CVE-2023-3934530Monitor
Unauthorized Access to Private Fields in User Registration API in strapi
HighCVSS 7.5No exploitEPSS 1%strapi · strapiNov 6, 2023
- CVE-2024-5258830Monitor
Strapi allows Server-Side Request Forgery in Webhook function
HighCVSS 7.5No exploitEPSS 1%strapi · strapiMay 29, 2025
- CVE-2023-3409328Monitor
Strapi allows actors to make all attributes on a content-type public without noticing it
HighCVSS 7.1No exploitEPSS 1%strapi · strapiJul 25, 2023
- CVE-2025-6452627Monitor
Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying
MediumCVSS 6.9No exploitEPSS 0%strapi · strapiMay 14, 2026
- CVE-2020-1396126Monitor
Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global var
MediumCVSS 6.5No exploitEPSS 2%strapi · strapiJun 19, 2020