İçeriğe atla
Noroxi

strapi kayıtları

strapi üreticisine ait 40 yayımlanmış kayıt.

Tüm kayıtlar

40 kayıt
  • CVE-2019-18818
    68Bu hafta

    strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-p

    KritikCVSS 9,8SilahlaştırılmışEPSS %98

    strapi · strapi7 Kas 2019

  • CVE-2023-22621
    49Planlayın

    Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the serve

    YüksekCVSS 7,2Kavram kanıtıEPSS %71

    strapi · strapi19 Nis 2023

  • CVE-2019-19609
    44Planlayın

    The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Adm

    YüksekCVSS 7,2Kavram kanıtıEPSS %54

    strapi · strapi5 Ara 2019

  • CVE-2022-27263
    40Planlayın

    An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted f

    KritikCVSS 9,8İstismar yokEPSS %3

    strapi · strapi12 Nis 2022

  • CVE-2020-27664
    40Planlayın

    admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.

    KritikCVSS 9,8İstismar yokEPSS %2

    strapi · strapi22 Eki 2020

  • CVE-2023-38507
    39İzleyin

    Strapi Improper Rate Limiting vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    strapi · strapi15 Eyl 2023

  • CVE-2026-27886
    37İzleyin

    Strapi may leak sensitive data via relational filtering due to lack of query sanitization

    KritikCVSS 9,2Kavram kanıtıEPSS %3

    strapi · strapi14 May 2026

  • CVE-2026-22599
    37İzleyin

    Strapi Vulnerable to SQL Injection in Content Type Builder

    KritikCVSS 9,3Kavram kanıtıEPSS %1

    strapi · strapi14 May 2026

  • CVE-2022-32114
    36İzleyin

    An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a craf

    YüksekCVSS 8,8Kavram kanıtıEPSS %2

    strapi · strapi13 Tem 2022

  • CVE-2022-31367
    36İzleyin

    Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.

    YüksekCVSS 8,8İstismar yokEPSS %2

    strapi · strapi27 Eyl 2022

  • CVE-2022-30617
    35İzleyin

    An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo

    YüksekCVSS 8,8İstismar yokEPSS %1

    strapi · strapi19 May 2022

  • CVE-2024-37818
    34İzleyin

    Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image.

    YüksekCVSS 8,6İstismar yokEPSS %1

    strapi · strapi20 Haz 2024

  • CVE-2021-28128
    32İzleyin

    In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password.

    YüksekCVSS 8,1İstismar yokEPSS %1

    strapi · strapi6 May 2021

  • CVE-2024-34065
    32İzleyin

    @strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass

    YüksekCVSS 8,1İstismar yokEPSS %1

    strapi · strapi12 Haz 2024

  • CVE-2024-56143
    32İzleyin

    Strapi Allows Unauthorized Access to Private Fields via parms.lookup

    YüksekCVSS 8,2İstismar yokEPSS %0

    strapi · strapi16 Eki 2025

  • CVE-2023-22893
    31İzleyin

    Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for au

    YüksekCVSS 7,5Kavram kanıtıEPSS %4

    strapi · strapi19 Nis 2023

  • CVE-2021-46440
    31İzleyin

    Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attack

    YüksekCVSS 7,5İstismar yokEPSS %3

    strapi · strapi3 May 2022

  • CVE-2020-27665
    30İzleyin

    In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.

    YüksekCVSS 7,5İstismar yokEPSS %1

    strapi · strapi22 Eki 2020

  • CVE-2023-34235
    30İzleyin

    Leaking sensitive user information still possible by filtering on private with prefix fields

    YüksekCVSS 7,5İstismar yokEPSS %1

    strapi · strapi25 Tem 2023

  • CVE-2022-30618
    30İzleyin

    An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo

    YüksekCVSS 7,5İstismar yokEPSS %1

    strapi · strapi19 May 2022

  • CVE-2023-39345
    30İzleyin

    Unauthorized Access to Private Fields in User Registration API in strapi

    YüksekCVSS 7,5İstismar yokEPSS %1

    strapi · strapi6 Kas 2023

  • CVE-2024-52588
    30İzleyin

    Strapi allows Server-Side Request Forgery in Webhook function

    YüksekCVSS 7,5İstismar yokEPSS %1

    strapi · strapi29 May 2025

  • CVE-2023-34093
    28İzleyin

    Strapi allows actors to make all attributes on a content-type public without noticing it

    YüksekCVSS 7,1İstismar yokEPSS %1

    strapi · strapi25 Tem 2023

  • CVE-2025-64526
    27İzleyin

    Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying

    OrtaCVSS 6,9İstismar yokEPSS %0

    strapi · strapi14 May 2026

  • CVE-2020-13961
    26İzleyin

    Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global var

    OrtaCVSS 6,5İstismar yokEPSS %2

    strapi · strapi19 Haz 2020