Vulnerabilities > Strapi > High

DATE CVE VULNERABILITY TITLE RISK
2024-06-12 CVE-2024-34065 Authentication Bypass by Capture-replay vulnerability in Strapi
Strapi is an open-source content management system.
network
low complexity
strapi CWE-294
8.1
2023-11-06 CVE-2023-39345 Unspecified vulnerability in Strapi
strapi is an open-source headless CMS.
network
low complexity
strapi
7.5
2023-07-25 CVE-2023-34235 Unspecified vulnerability in Strapi
Strapi is an open-source headless content management system.
network
low complexity
strapi
7.5
2023-07-25 CVE-2023-34093 Unspecified vulnerability in Strapi
Strapi is an open-source headless content management system.
network
low complexity
strapi
7.1
2023-04-19 CVE-2023-22621 Injection vulnerability in Strapi
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server.
network
low complexity
strapi CWE-74
7.2
2023-04-19 CVE-2023-22893 Improper Authentication vulnerability in Strapi
Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication.
network
low complexity
strapi CWE-287
7.5
2022-09-27 CVE-2022-31367 SQL Injection vulnerability in Strapi
Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.
network
low complexity
strapi CWE-89
8.8
2022-07-13 CVE-2022-32114 Unrestricted Upload of File with Dangerous Type vulnerability in Strapi 4.1.12
An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file.
network
low complexity
strapi CWE-434
8.8
2022-05-19 CVE-2022-30617 Improper Cross-boundary Removal of Sensitive Data vulnerability in Strapi
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for other admin panel users that have a relationship (e.g., created by, updated by) with content accessible to the authenticated user.
network
low complexity
strapi CWE-212
8.8
2022-05-19 CVE-2022-30618 Improper Cross-boundary Removal of Sensitive Data vulnerability in Strapi
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for API users if content types accessible to the authenticated user contain relationships to API users (from:users-permissions).
network
high complexity
strapi CWE-212
7.5