📦 Strapi

by Strapi

🔍 What is Strapi?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-27664

CRITICAL CVSS 9.8 Oct 22, 2020

CVE-2020-27664 is a server-side request forgery (SSRF) vulnerability in Strapi's admin interface that allows attackers to make unauthorized requests to internal systems. It affects Strapi installation...

CVE-2024-56143

HIGH CVSS 8.2 Oct 16, 2025

This vulnerability in Strapi allows attackers to access private fields like admin passwords and reset tokens by crafting malicious queries with the lookup parameter. It affects Strapi versions 5.0.0 t...

CVE-2024-37818

HIGH CVSS 8.6 Jun 20, 2024

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Strapi v4.24.4 that allows attackers to make unauthorized requests from the server to internal systems via the /strapi.io/_next...

CVE-2024-34065

HIGH CVSS 7.1 Jun 12, 2024

This CVE describes an authentication bypass vulnerability in Strapi's users-permissions plugin. By combining an open redirect with session tokens sent as URL parameters, unauthenticated attackers can ...

CVE-2023-39345

HIGH CVSS 7.6 Nov 6, 2023

This vulnerability in Strapi allows malicious users to modify private fields in their user records during registration. It affects all Strapi instances running versions before 4.13.1 where user regist...

CVE-2023-38507

HIGH CVSS 7.3 Sep 15, 2023

This vulnerability allows attackers to bypass rate limiting on Strapi's admin login function, enabling brute force attacks to guess credentials. It affects all Strapi deployments with admin interfaces...

CVE-2023-22621

HIGH CVSS 7.2 Apr 19, 2023

CVE-2023-22621 is a Server-Side Template Injection vulnerability in Strapi that allows authenticated attackers with admin panel access to execute arbitrary code on the server by injecting malicious pa...

CVE-2022-32114

HIGH CVSS 8.8 Jul 13, 2022

An unrestricted file upload vulnerability in Strapi 4.1.12 allows authenticated users with upload permissions to upload PDF files containing JavaScript, which can lead to cross-site scripting (XSS) at...

CVE-2021-46440

HIGH CVSS 7.5 May 3, 2022

This vulnerability in Strapi's DOCUMENTATION plugin stores passwords in a recoverable format (base64 encoded in cookies). Attackers who intercept HTTP requests can decode cookies to obtain cleartext p...

CVE-2021-28128

HIGH CVSS 8.1 May 6, 2021

This vulnerability in Strapi allows attackers who have obtained a valid session to change a user's password without providing the current password. This enables account takeover attacks where attacker...

CVE-2025-25298

MEDIUM CVSS 5.3 Oct 16, 2025

Strapi versions before 5.10.3 do not enforce a maximum password length when using bcryptjs for password hashing, causing passwords longer than 72 bytes to be silently truncated. This reduces effective...