Записи strapi
40 опубликованных записей вендора strapi.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 2,5 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 87,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-287 Improper Authentication2
- CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer2
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
40 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
68На этой неделе | CVE-2019-18818Готовый эксплойт | strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-pstrapi · strapi · CWE-640 | Критическая9,8 | — | 97,6 % | 7 нояб. 2019 г. |
49В плане | CVE-2023-22621Proof of concept | Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the servestrapi · strapi · CWE-74 | Высокая7,2 | — | 70,6 % | 19 апр. 2023 г. |
44В плане | CVE-2019-19609Proof of concept | The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admstrapi · strapi · CWE-78 | Высокая7,2 | — | 54,1 % | 5 дек. 2019 г. |
40В плане | CVE-2022-27263Эксплойта нет | An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted fstrapi · strapi · CWE-434 | Критическая9,8 | — | 3,2 % | 12 апр. 2022 г. |
40В плане | CVE-2020-27664Эксплойта нет | admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.strapi · strapi | Критическая9,8 | — | 2,3 % | 22 окт. 2020 г. |
39Наблюдать | CVE-2023-38507Эксплойта нет | Strapi Improper Rate Limiting vulnerabilitystrapi · strapi · CWE-770 | Критическая9,8 | — | 1,0 % | 15 сент. 2023 г. |
37Наблюдать | CVE-2026-27886Proof of concept | Strapi may leak sensitive data via relational filtering due to lack of query sanitizationstrapi · strapi · CWE-22 | Критическая9,2 | — | 2,5 % | 14 мая 2026 г. |
37Наблюдать | CVE-2026-22599Proof of concept | Strapi Vulnerable to SQL Injection in Content Type Builderstrapi · strapi · CWE-89 | Критическая9,3 | — | 1,2 % | 14 мая 2026 г. |
36Наблюдать | CVE-2022-32114Proof of concept | An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafstrapi · strapi · CWE-434 | Высокая8,8 | — | 2,0 % | 13 июл. 2022 г. |
36Наблюдать | CVE-2022-31367Эксплойта нет | Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.strapi · strapi · CWE-89 | Высокая8,8 | — | 1,7 % | 27 сент. 2022 г. |
35Наблюдать | CVE-2022-30617Эксплойта нет | An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fostrapi · strapi · CWE-212 | Высокая8,8 | — | 1,5 % | 19 мая 2022 г. |
34Наблюдать | CVE-2024-37818Эксплойта нет | Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image.strapi · strapi · CWE-918 | Высокая8,6 | — | 0,6 % | 20 июн. 2024 г. |
32Наблюдать | CVE-2021-28128Эксплойта нет | In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password.strapi · strapi · CWE-640 | Высокая8,1 | — | 1,3 % | 6 мая 2021 г. |
32Наблюдать | CVE-2024-34065Эксплойта нет | @strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypassstrapi · strapi · CWE-294 | Высокая8,1 | — | 0,7 % | 12 июн. 2024 г. |
32Наблюдать | CVE-2024-56143Эксплойта нет | Strapi Allows Unauthorized Access to Private Fields via parms.lookupstrapi · strapi · CWE-639 | Высокая8,2 | — | 0,4 % | 16 окт. 2025 г. |
31Наблюдать | CVE-2023-22893Proof of concept | Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for austrapi · strapi · CWE-287 | Высокая7,5 | — | 4,1 % | 19 апр. 2023 г. |
31Наблюдать | CVE-2021-46440Эксплойта нет | Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attackstrapi · strapi · CWE-522 | Высокая7,5 | — | 2,9 % | 3 мая 2022 г. |
30Наблюдать | CVE-2020-27665Эксплойта нет | In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.strapi · strapi · CWE-276 | Высокая7,5 | — | 1,2 % | 22 окт. 2020 г. |
30Наблюдать | CVE-2023-34235Эксплойта нет | Leaking sensitive user information still possible by filtering on private with prefix fieldsstrapi · strapi · CWE-200 | Высокая7,5 | — | 1,1 % | 25 июл. 2023 г. |
30Наблюдать | CVE-2022-30618Эксплойта нет | An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fostrapi · strapi · CWE-212 | Высокая7,5 | — | 0,9 % | 19 мая 2022 г. |
30Наблюдать | CVE-2023-39345Эксплойта нет | Unauthorized Access to Private Fields in User Registration API in strapistrapi · strapi · CWE-287 | Высокая7,5 | — | 0,6 % | 6 нояб. 2023 г. |
30Наблюдать | CVE-2024-52588Эксплойта нет | Strapi allows Server-Side Request Forgery in Webhook functionstrapi · strapi · CWE-918 | Высокая7,5 | — | 0,6 % | 29 мая 2025 г. |
28Наблюдать | CVE-2023-34093Эксплойта нет | Strapi allows actors to make all attributes on a content-type public without noticing itstrapi · strapi · CWE-200 | Высокая7,1 | — | 0,7 % | 25 июл. 2023 г. |
27Наблюдать | CVE-2025-64526Эксплойта нет | Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keyingstrapi · strapi · CWE-307 | Средняя6,9 | — | 0,5 % | 14 мая 2026 г. |
26Наблюдать | CVE-2020-13961Эксплойта нет | Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global varstrapi · strapi · CWE-20 | Средняя6,5 | — | 1,7 % | 19 июн. 2020 г. |
- CVE-2019-1881868На этой неделе
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-p
КритическаяCVSS 9,8Готовый эксплойтEPSS 98 %strapi · strapi7 нояб. 2019 г.
- CVE-2023-2262149В плане
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the serve
ВысокаяCVSS 7,2Proof of conceptEPSS 71 %strapi · strapi19 апр. 2023 г.
- CVE-2019-1960944В плане
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Adm
ВысокаяCVSS 7,2Proof of conceptEPSS 54 %strapi · strapi5 дек. 2019 г.
- CVE-2022-2726340В плане
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted f
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %strapi · strapi12 апр. 2022 г.
- CVE-2020-2766440В плане
admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %strapi · strapi22 окт. 2020 г.
- CVE-2023-3850739Наблюдать
Strapi Improper Rate Limiting vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %strapi · strapi15 сент. 2023 г.
- CVE-2026-2788637Наблюдать
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
КритическаяCVSS 9,2Proof of conceptEPSS 3 %strapi · strapi14 мая 2026 г.
- CVE-2026-2259937Наблюдать
Strapi Vulnerable to SQL Injection in Content Type Builder
КритическаяCVSS 9,3Proof of conceptEPSS 1 %strapi · strapi14 мая 2026 г.
- CVE-2022-3211436Наблюдать
An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a craf
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %strapi · strapi13 июл. 2022 г.
- CVE-2022-3136736Наблюдать
Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %strapi · strapi27 сент. 2022 г.
- CVE-2022-3061735Наблюдать
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %strapi · strapi19 мая 2022 г.
- CVE-2024-3781834Наблюдать
Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %strapi · strapi20 июн. 2024 г.
- CVE-2021-2812832Наблюдать
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %strapi · strapi6 мая 2021 г.
- CVE-2024-3406532Наблюдать
@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %strapi · strapi12 июн. 2024 г.
- CVE-2024-5614332Наблюдать
Strapi Allows Unauthorized Access to Private Fields via parms.lookup
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %strapi · strapi16 окт. 2025 г.
- CVE-2023-2289331Наблюдать
Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for au
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %strapi · strapi19 апр. 2023 г.
- CVE-2021-4644031Наблюдать
Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attack
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %strapi · strapi3 мая 2022 г.
- CVE-2020-2766530Наблюдать
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %strapi · strapi22 окт. 2020 г.
- CVE-2023-3423530Наблюдать
Leaking sensitive user information still possible by filtering on private with prefix fields
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %strapi · strapi25 июл. 2023 г.
- CVE-2022-3061830Наблюдать
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %strapi · strapi19 мая 2022 г.
- CVE-2023-3934530Наблюдать
Unauthorized Access to Private Fields in User Registration API in strapi
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %strapi · strapi6 нояб. 2023 г.
- CVE-2024-5258830Наблюдать
Strapi allows Server-Side Request Forgery in Webhook function
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %strapi · strapi29 мая 2025 г.
- CVE-2023-3409328Наблюдать
Strapi allows actors to make all attributes on a content-type public without noticing it
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %strapi · strapi25 июл. 2023 г.
- CVE-2025-6452627Наблюдать
Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying
СредняяCVSS 6,9Эксплойта нетEPSS 0 %strapi · strapi14 мая 2026 г.
- CVE-2020-1396126Наблюдать
Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global var
СредняяCVSS 6,5Эксплойта нетEPSS 2 %strapi · strapi19 июн. 2020 г.