Vulnerabilities > Strapi > Strapi > 1.5.1

DATE CVE VULNERABILITY TITLE RISK
2023-09-15 CVE-2023-38507 Allocation of Resources Without Limits or Throttling vulnerability in Strapi
Strapi is the an open-source headless content management system.
network
low complexity
strapi CWE-770
critical
9.8
2023-09-15 CVE-2023-36472 Information Exposure vulnerability in Strapi
Strapi is an open-source headless content management system.
network
low complexity
strapi CWE-200
5.7
2023-09-15 CVE-2023-37263 Unspecified vulnerability in Strapi
Strapi is the an open-source headless content management system.
network
low complexity
strapi
2.7
2023-07-25 CVE-2023-34235 Information Exposure vulnerability in Strapi
Strapi is an open-source headless content management system.
network
low complexity
strapi CWE-200
7.5
2023-07-25 CVE-2023-34093 Information Exposure vulnerability in Strapi
Strapi is an open-source headless content management system.
network
low complexity
strapi CWE-200
7.1
2022-09-27 CVE-2022-31367 SQL Injection vulnerability in Strapi
Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.
network
low complexity
strapi CWE-89
8.8
2022-06-13 CVE-2022-29894 Cross-site Scripting vulnerability in Strapi
Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function.
network
strapi CWE-79
3.5
2022-05-03 CVE-2021-46440 Insufficiently Protected Credentials vulnerability in Strapi
Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, get the victim's cookie, perform a base64 decode on the victim's cookie, and obtain a cleartext password, leading to getting API documentation for further API attacks.
network
low complexity
strapi CWE-522
5.0
2022-02-26 CVE-2022-0764 Unspecified vulnerability in Strapi
Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.
local
low complexity
strapi
6.7
2021-05-06 CVE-2021-28128 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Strapi
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password.
network
low complexity
strapi CWE-640
5.5