Known vulnerabilities in strapi.io strapi

Vendor: strapi.io
Website: https://strapi.io/
Total Security Bulletins: 29

Security bulletins (29)

Secuity bulletin Severity Status Published
SB2026051395: Improper Restriction of Excessive Authentication Attempts in strapi Medium
Patched
13.05.2026
SB2026051394: SQL injection in strapi Low
Patched
13.05.2026
SB2026051393: Multiple vulnerabilities in strapi Low
Patched
13.05.2026
SB2026051392: Improper Neutralization of Special Elements in Data Query Logic in strapi High
Patched
13.05.2026
SB2026042379: Weak Encoding for Password in strapi Low
Patched
23.04.2026
SB2026042378: Improper access control in strapi High
Patched
23.04.2026
SB2026042377: Overly permissive cross-domain whitelist in strapi Medium
Patched
23.04.2026
SB2025052762: SSRF in Strapi Low
Patched
27.05.2025
SB2025032417: Strapi update for axios Medium
Patched Public exploit
24.03.2025
SB2024061246: Open redirect in strapi Medium
Patched
12.06.2024
SB2024061245: Uncaught Exception in strapi Low
Patched
12.06.2024
SB2024061244: Improper access control in strapi Low
Patched
12.06.2024
SB2023110622: Improper access control in Strapi Medium
Patched
06.11.2023
SB2023091375: Improper access control in strapi Low
Patched
13.09.2023
SB2023091374: Multiple vulnerabilities in strapi Medium
Patched
13.09.2023
SB2023072819: Multiple vulnerabilities in strapi High
Patched
28.07.2023
SB2023050329: Remote code execution in Strapi High
Patched Public exploit
03.05.2023
SB2023050328: Improper Authentication in Strapi High
Patched
03.05.2023
SB2023050327: Information disclosure in Strapi Medium
Patched Public exploit
03.05.2023
SB2023013044: Strapi update for Knex High
Patched
30.01.2023


Showing elements 1 - 20 out of 29