Known vulnerabilities in strapi

Vendor: strapi.io
Software: strapi
Software CPE: cpe:2.3:a:strapi.io:strapi:*:*:*:*:*:*:*:*
Total vulnerabilities: 37
Public exploits: 8
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting strapi strapi is affected by 37 known vulnerabilities: 11 high, 14 medium, 12 low Critical High Medium Low

Vulnerabilities (37)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU131370 - Improper Restriction of Excessive Authentication Attempts
CVE-2025-64526
CWE-307 Medium
No
No
5.45.0 13.05.2026 SB2026051395
#VU131369 - Insufficient Session Expiration
CVE-2026-22706
CWE-613 Low
No
No
5.33.3 13.05.2026 SB2026051393
#VU131368 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-22599
CWE-89 Low
No
No
4.26.1, 5.33.2 13.05.2026 SB2026051394
#VU131365 - Unrestricted Upload of File with Dangerous Type
CVE-2026-22707
CWE-434 Low
No
No
5.33.3 13.05.2026 SB2026051393
#VU131364 - Improper Neutralization of Special Elements in Data Query Logic
CVE-2026-27886
CWE-943 High
No
No
5.37.0 13.05.2026 SB2026051392
#VU126969 - Weak Cryptography for Passwords
CVE-2025-25298
CWE-261 Low
No
No
5.10.3 23.04.2026 SB2026042379
#VU126968 - Improper Access Control
CVE-2024-56143
CWE-284 High
No
No
5.5.2 23.04.2026 SB2026042378
#VU126967 - Overly Permissive Cross-domain Whitelist
CVE-2025-53092
CWE-942 Medium
No
No
5.20.0 23.04.2026 SB2026042377
#VU109863 - Server-Side Request Forgery (SSRF)
CVE-2024-52588
CWE-918 Low
No
No
4.25.2 27.05.2025 SB2025052762
#VU105452 - Server-Side Request Forgery (SSRF)
CVE-2025-27152
CWE-918 Medium
Available
No
4.25.22 07.03.2025 SB2025030777
SB2025031918
SB2025032417
and 42 more
#VU126964 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-34065
CWE-601 Medium
No
No
4.24.2 12.06.2024 SB2024061246
#VU126965 - Uncaught Exception
CVE-2024-31217
CWE-248 Low
No
No
4.22.0 12.06.2024 SB2024061245
#VU126966 - Improper Access Control
CVE-2024-29181
CWE-284 Low
No
No
4.19.1 12.06.2024 SB2024061244
#VU82733 - Improper Access Control
CVE-2023-39345
CWE-284 Medium
No
No
4.13.1 06.11.2023 SB2023110622
#VU126961 - Improper Access Control
CVE-2023-37263
CWE-284 Low
No
No
4.12.1 13.09.2023 SB2023091374
#VU126962 - Improper Access Control
CVE-2023-36472
CWE-284 Low
No
No
4.11.7 13.09.2023 SB2023091375
#VU126963 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-38507
CWE-307 Medium
No
No
4.12.1 13.09.2023 SB2023091374
#VU78744 - Exposure of sensitive information to an unauthorized actor
CVE-2023-34235
CWE-200 High
No
No
4.10.8 28.07.2023 SB2023072819
#VU78743 - Exposure of sensitive information to an unauthorized actor
CVE-2023-34093
CWE-200 Low
No
No
4.10.8 28.07.2023 SB2023072819
#VU75701 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-22621
CWE-94 High
Available
No
4.5.6 03.05.2023 SB2023050329


Showing elements 1 - 20 out of 37