CVEs we hold for Strapi
Records whose assigning authority named Strapi as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-57997Strapi users-permissions - JWT Algorithm Confusion via Missing Algorithm Configurationstrapi
CVE-2026-27886Strapi may leak sensitive data via relational filtering due to lack of query sanitizationstrapi
CVE-2026-22707Strapi Upload Plugin MIME Validation Bypass via Content APIstrapi; strapi @strapi/upload
CVE-2026-22706Strapi: Password Reset Does Not Revoke Existing Refresh Sessionsstrapi; strapi @strapi/admin; strapi…
CVE-2026-22599Strapi Vulnerable to SQL Injection in Content Type Builderstrapi; strapi @strapi/content-type-builder
CVE-2025-64526Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keyingstrapi; strapi @strapi/plugin-users-permissions
CVE-2024-34065@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypassstrapi
CVE-2023-48218Strapi Protected Populate Plugin leaking fields if the request fields where empty or only fields selected where not…strapi-community strapi-plugin-protected-populate
CVE-2023-36472Strapi may leak sensitive user information, user reset password, tokens via content-manager viewsstrapi
CVE-2023-34235Leaking sensitive user information still possible by filtering on private with prefix fieldsstrapi
CVE-2023-34093Strapi allows actors to make all attributes on a content-type public without noticing itstrapi
27 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.