strapi kayıtları
strapi üreticisine ait 40 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %2,5
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %87,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-287 Improper Authentication2
- CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer2
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
40 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
68Bu hafta | CVE-2019-18818Silahlaştırılmış | strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-pstrapi · strapi · CWE-640 | Kritik9,8 | — | %97,6 | 7 Kas 2019 |
49Planlayın | CVE-2023-22621Kavram kanıtı | Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the servestrapi · strapi · CWE-74 | Yüksek7,2 | — | %70,6 | 19 Nis 2023 |
44Planlayın | CVE-2019-19609Kavram kanıtı | The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admstrapi · strapi · CWE-78 | Yüksek7,2 | — | %54,1 | 5 Ara 2019 |
40Planlayın | CVE-2022-27263İstismar yok | An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted fstrapi · strapi · CWE-434 | Kritik9,8 | — | %3,2 | 12 Nis 2022 |
40Planlayın | CVE-2020-27664İstismar yok | admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.strapi · strapi | Kritik9,8 | — | %2,3 | 22 Eki 2020 |
39İzleyin | CVE-2023-38507İstismar yok | Strapi Improper Rate Limiting vulnerabilitystrapi · strapi · CWE-770 | Kritik9,8 | — | %1,0 | 15 Eyl 2023 |
37İzleyin | CVE-2026-27886Kavram kanıtı | Strapi may leak sensitive data via relational filtering due to lack of query sanitizationstrapi · strapi · CWE-22 | Kritik9,2 | — | %2,5 | 14 May 2026 |
37İzleyin | CVE-2026-22599Kavram kanıtı | Strapi Vulnerable to SQL Injection in Content Type Builderstrapi · strapi · CWE-89 | Kritik9,3 | — | %1,2 | 14 May 2026 |
36İzleyin | CVE-2022-32114Kavram kanıtı | An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafstrapi · strapi · CWE-434 | Yüksek8,8 | — | %2,0 | 13 Tem 2022 |
36İzleyin | CVE-2022-31367İstismar yok | Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.strapi · strapi · CWE-89 | Yüksek8,8 | — | %1,7 | 27 Eyl 2022 |
35İzleyin | CVE-2022-30617İstismar yok | An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fostrapi · strapi · CWE-212 | Yüksek8,8 | — | %1,5 | 19 May 2022 |
34İzleyin | CVE-2024-37818İstismar yok | Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image.strapi · strapi · CWE-918 | Yüksek8,6 | — | %0,6 | 20 Haz 2024 |
32İzleyin | CVE-2021-28128İstismar yok | In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password.strapi · strapi · CWE-640 | Yüksek8,1 | — | %1,3 | 6 May 2021 |
32İzleyin | CVE-2024-34065İstismar yok | @strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypassstrapi · strapi · CWE-294 | Yüksek8,1 | — | %0,7 | 12 Haz 2024 |
32İzleyin | CVE-2024-56143İstismar yok | Strapi Allows Unauthorized Access to Private Fields via parms.lookupstrapi · strapi · CWE-639 | Yüksek8,2 | — | %0,4 | 16 Eki 2025 |
31İzleyin | CVE-2023-22893Kavram kanıtı | Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for austrapi · strapi · CWE-287 | Yüksek7,5 | — | %4,1 | 19 Nis 2023 |
31İzleyin | CVE-2021-46440İstismar yok | Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attackstrapi · strapi · CWE-522 | Yüksek7,5 | — | %2,9 | 3 May 2022 |
30İzleyin | CVE-2020-27665İstismar yok | In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.strapi · strapi · CWE-276 | Yüksek7,5 | — | %1,2 | 22 Eki 2020 |
30İzleyin | CVE-2023-34235İstismar yok | Leaking sensitive user information still possible by filtering on private with prefix fieldsstrapi · strapi · CWE-200 | Yüksek7,5 | — | %1,1 | 25 Tem 2023 |
30İzleyin | CVE-2022-30618İstismar yok | An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fostrapi · strapi · CWE-212 | Yüksek7,5 | — | %0,9 | 19 May 2022 |
30İzleyin | CVE-2023-39345İstismar yok | Unauthorized Access to Private Fields in User Registration API in strapistrapi · strapi · CWE-287 | Yüksek7,5 | — | %0,6 | 6 Kas 2023 |
30İzleyin | CVE-2024-52588İstismar yok | Strapi allows Server-Side Request Forgery in Webhook functionstrapi · strapi · CWE-918 | Yüksek7,5 | — | %0,6 | 29 May 2025 |
28İzleyin | CVE-2023-34093İstismar yok | Strapi allows actors to make all attributes on a content-type public without noticing itstrapi · strapi · CWE-200 | Yüksek7,1 | — | %0,7 | 25 Tem 2023 |
27İzleyin | CVE-2025-64526İstismar yok | Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keyingstrapi · strapi · CWE-307 | Orta6,9 | — | %0,5 | 14 May 2026 |
26İzleyin | CVE-2020-13961İstismar yok | Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global varstrapi · strapi · CWE-20 | Orta6,5 | — | %1,7 | 19 Haz 2020 |
- CVE-2019-1881868Bu hafta
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-p
KritikCVSS 9,8SilahlaştırılmışEPSS %98strapi · strapi7 Kas 2019
- CVE-2023-2262149Planlayın
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the serve
YüksekCVSS 7,2Kavram kanıtıEPSS %71strapi · strapi19 Nis 2023
- CVE-2019-1960944Planlayın
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Adm
YüksekCVSS 7,2Kavram kanıtıEPSS %54strapi · strapi5 Ara 2019
- CVE-2022-2726340Planlayın
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted f
KritikCVSS 9,8İstismar yokEPSS %3strapi · strapi12 Nis 2022
- CVE-2020-2766440Planlayın
admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.
KritikCVSS 9,8İstismar yokEPSS %2strapi · strapi22 Eki 2020
- CVE-2023-3850739İzleyin
Strapi Improper Rate Limiting vulnerability
KritikCVSS 9,8İstismar yokEPSS %1strapi · strapi15 Eyl 2023
- CVE-2026-2788637İzleyin
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
KritikCVSS 9,2Kavram kanıtıEPSS %3strapi · strapi14 May 2026
- CVE-2026-2259937İzleyin
Strapi Vulnerable to SQL Injection in Content Type Builder
KritikCVSS 9,3Kavram kanıtıEPSS %1strapi · strapi14 May 2026
- CVE-2022-3211436İzleyin
An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a craf
YüksekCVSS 8,8Kavram kanıtıEPSS %2strapi · strapi13 Tem 2022
- CVE-2022-3136736İzleyin
Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.
YüksekCVSS 8,8İstismar yokEPSS %2strapi · strapi27 Eyl 2022
- CVE-2022-3061735İzleyin
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo
YüksekCVSS 8,8İstismar yokEPSS %1strapi · strapi19 May 2022
- CVE-2024-3781834İzleyin
Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image.
YüksekCVSS 8,6İstismar yokEPSS %1strapi · strapi20 Haz 2024
- CVE-2021-2812832İzleyin
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password.
YüksekCVSS 8,1İstismar yokEPSS %1strapi · strapi6 May 2021
- CVE-2024-3406532İzleyin
@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass
YüksekCVSS 8,1İstismar yokEPSS %1strapi · strapi12 Haz 2024
- CVE-2024-5614332İzleyin
Strapi Allows Unauthorized Access to Private Fields via parms.lookup
YüksekCVSS 8,2İstismar yokEPSS %0strapi · strapi16 Eki 2025
- CVE-2023-2289331İzleyin
Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for au
YüksekCVSS 7,5Kavram kanıtıEPSS %4strapi · strapi19 Nis 2023
- CVE-2021-4644031İzleyin
Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attack
YüksekCVSS 7,5İstismar yokEPSS %3strapi · strapi3 May 2022
- CVE-2020-2766530İzleyin
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
YüksekCVSS 7,5İstismar yokEPSS %1strapi · strapi22 Eki 2020
- CVE-2023-3423530İzleyin
Leaking sensitive user information still possible by filtering on private with prefix fields
YüksekCVSS 7,5İstismar yokEPSS %1strapi · strapi25 Tem 2023
- CVE-2022-3061830İzleyin
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo
YüksekCVSS 7,5İstismar yokEPSS %1strapi · strapi19 May 2022
- CVE-2023-3934530İzleyin
Unauthorized Access to Private Fields in User Registration API in strapi
YüksekCVSS 7,5İstismar yokEPSS %1strapi · strapi6 Kas 2023
- CVE-2024-5258830İzleyin
Strapi allows Server-Side Request Forgery in Webhook function
YüksekCVSS 7,5İstismar yokEPSS %1strapi · strapi29 May 2025
- CVE-2023-3409328İzleyin
Strapi allows actors to make all attributes on a content-type public without noticing it
YüksekCVSS 7,1İstismar yokEPSS %1strapi · strapi25 Tem 2023
- CVE-2025-6452627İzleyin
Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying
OrtaCVSS 6,9İstismar yokEPSS %0strapi · strapi14 May 2026
- CVE-2020-1396126İzleyin
Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global var
OrtaCVSS 6,5İstismar yokEPSS %2strapi · strapi19 Haz 2020