Vulnerabilities > Strapi

DATE CVE VULNERABILITY TITLE RISK
2022-02-26 CVE-2022-0764 Unspecified vulnerability in Strapi
Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.
local
low complexity
strapi
6.7
2021-05-06 CVE-2021-28128 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Strapi
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password.
network
low complexity
strapi CWE-640
8.1
2020-10-22 CVE-2020-27666 Cross-site Scripting vulnerability in Strapi
Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.
network
low complexity
strapi CWE-79
5.4
2020-10-22 CVE-2020-27665 Incorrect Default Permissions vulnerability in Strapi
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
network
low complexity
strapi CWE-276
7.5
2020-10-22 CVE-2020-27664 Unspecified vulnerability in Strapi
admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.
network
low complexity
strapi
critical
9.8
2020-06-19 CVE-2020-13961 Improper Input Validation vulnerability in Strapi
Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global variable without any sanitation.
network
low complexity
strapi CWE-20
6.5
2020-02-04 CVE-2020-8123 Resource Exhaustion vulnerability in Strapi
A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin rights can lead to arbitrary restart of the application.
network
low complexity
strapi CWE-400
4.9
2019-12-05 CVE-2019-19609 OS Command Injection vulnerability in Strapi
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa function.
network
low complexity
strapi CWE-78
7.2
2019-11-07 CVE-2019-18818 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Strapi
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
network
low complexity
strapi CWE-640
critical
9.8