vciy

CVEs we hold for Strapi

Records whose assigning authority named Strapi as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-90561Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYGstrapi
CVE-2026-57997Strapi users-permissions - JWT Algorithm Confusion via Missing Algorithm Configurationstrapi
CVE-2026-27886Strapi may leak sensitive data via relational filtering due to lack of query sanitizationstrapi
CVE-2026-22707Strapi Upload Plugin MIME Validation Bypass via Content APIstrapi; strapi @strapi/upload
CVE-2026-22706Strapi: Password Reset Does Not Revoke Existing Refresh Sessionsstrapi; strapi @strapi/admin; strapi…
CVE-2026-22599Strapi Vulnerable to SQL Injection in Content Type Builderstrapi; strapi @strapi/content-type-builder
CVE-2025-64526Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keyingstrapi; strapi @strapi/plugin-users-permissions
CVE-2025-53092Strapi core vulnerable to sensitive data exposure via CORS misconfigurationstrapi
CVE-2025-3930Lack of JWT Expiration after Log Out in StrapiStrapi
CVE-2025-25298Missing Maximum Password Length Validation in Strapi Password Hashingstrapi
CVE-2024-56143Strapi Allows Unauthorized Access to Private Fields via parms.lookupstrapi
CVE-2024-52588Strapi allows Server-Side Request Forgery in Webhook functionstrapi
CVE-2024-34065@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypassstrapi
CVE-2024-31217@strapi/plugin-upload has a Denial-of-Service via Improper Exception Handlingstrapi
CVE-2024-29181@strapi/plugin-content-manager leaks data via relations via the Admin Panelstrapi
CVE-2023-48218Strapi Protected Populate Plugin leaking fields if the request fields where empty or only fields selected where not…strapi-community strapi-plugin-protected-populate
CVE-2023-39345Unauthorized Access to Private Fields in User Registration API in strapistrapi
CVE-2023-38507Strapi Improper Rate Limiting vulnerabilitystrapi
CVE-2023-37263Strapi's field level permissions not being respected in relationship titlestrapi
CVE-2023-36472Strapi may leak sensitive user information, user reset password, tokens via content-manager viewsstrapi
CVE-2023-34235Leaking sensitive user information still possible by filtering on private with prefix fieldsstrapi
CVE-2023-34093Strapi allows actors to make all attributes on a content-type public without noticing itstrapi
CVE-2022-30618no title heldStrapi
CVE-2022-30617no title heldStrapi
CVE-2022-29894no title heldStrapi
CVE-2022-0764Arbitrary Command Injection in strapi/strapistrapi/strapi
CVE-2020-8123no title heldn/a Strapi

27 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.