Monospace Security Vulnerabilities (CVEs)

Track 23 security vulnerabilities affecting Monospace products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

1 Critical
3 High
19 Medium
🔔 Get Alerts for Monospace
CVE-2026-26185 5.3

This timing-based user enumeration vulnerability in Directus allows attackers to determine whether specific usernames/emails exist in the system by me...

Feb 12, 2026
CVE-2026-22032 4.3

An open redirect vulnerability in Directus SAML authentication allows attackers to redirect users to malicious external websites after authentication....

Jan 8, 2026
CVE-2025-64747 5.5

A stored cross-site scripting (XSS) vulnerability in Directus allows authenticated users with file upload and edit permissions to inject malicious Jav...

Nov 13, 2025
CVE-2025-64748 6.5

This vulnerability in Directus allows authenticated users with read permissions to detect matches in concealed/sensitive fields through search functio...

Nov 13, 2025
CVE-2025-64749 4.3

This CVE describes an information disclosure vulnerability in Directus where unauthorized users can determine whether specific database collections ex...

Nov 13, 2025
CVE-2025-64746 4.6

A permission inheritance vulnerability in Directus allows stale field-level permissions to persist after field deletion. When a deleted field's name i...

Nov 13, 2025
CVE-2025-55746 9.3

This vulnerability allows unauthenticated attackers to modify existing files with arbitrary content or upload new files with arbitrary content and ext...

Aug 20, 2025
CVE-2025-53886 4.5

This vulnerability in Directus logs sensitive authentication tokens when using WebHook triggers in Flows, exposing access and refresh tokens in system...

Jul 15, 2025
CVE-2025-53889 6.5

Directus versions 9.12.0 through 11.8.0 have an authentication bypass vulnerability in manual trigger Flows. Attackers can execute Flows without prope...

Jul 15, 2025
CVE-2025-30352 5.3

This vulnerability in Directus allows authenticated users to enumerate database field contents they shouldn't have permission to view. By exploiting t...

Mar 26, 2025
CVE-2025-30353 8.6

This vulnerability in Directus exposes sensitive data including environmental variables, API keys, and user information when a Flow with a Webhook tri...

Mar 26, 2025
CVE-2025-30225 5.3

This vulnerability in Directus's S3 storage driver allows attackers to cause denial of service for all assets by sending multiple malformed transforma...

Mar 26, 2025
CVE-2025-27089 5.4

This vulnerability in Directus allows users with overlapping update permissions to modify fields they shouldn't have access to. When multiple policies...

Feb 19, 2025
CVE-2025-24353 5.0

This vulnerability in Directus allows users with typical permissions to specify arbitrary roles when sharing items, potentially granting access to fie...

Jan 23, 2025
CVE-2024-54151 7.5

This vulnerability in Directus allows unauthenticated users to perform any CRUD operations or subscribe to data changes with full admin privileges whe...

Dec 9, 2024
CVE-2024-54128 5.7

CVE-2024-54128 is an HTML injection vulnerability in Directus's comment feature due to client-side filtering that can be bypassed. This allows attacke...

Dec 5, 2024
CVE-2024-47822 4.2

Directus systems with LOG_STYLE set to 'raw' expose access tokens in query strings within system logs. Attackers with log access can steal these token...

Oct 8, 2024
CVE-2024-46990 5.0

This vulnerability in Directus allows attackers to bypass localhost access restrictions by using alternative loopback IP addresses like 127.0.0.2 inst...

Sep 18, 2024
CVE-2024-6533 5.4

CVE-2024-6533 is a stored cross-site scripting (XSS) vulnerability in Directus v10.13.0 that allows authenticated attackers to inject malicious JavaSc...

Aug 15, 2024
CVE-2024-39701 6.3

This vulnerability in Directus allows broken access control when using _in or _nin operators with empty arrays. Attackers can bypass intended permissi...

Jul 8, 2024
CVE-2024-39699 5.0

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Directus that allows attackers to bypass DNS resolution protections via HTTP ...

Jul 8, 2024
CVE-2024-34708 4.9

This vulnerability in Directus allows users with permission to view collections containing redacted hashed fields to bypass redaction and access the p...

May 14, 2024
CVE-2024-27295 8.2

This vulnerability in Directus allows attackers to hijack password reset emails by using email addresses with accented characters that MySQL/MariaDB t...

Mar 1, 2024

Why Monitor Monospace Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 23+ known vulnerabilities affecting Monospace products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Monospace packages in under 60 seconds. No agents required - completely agentless scanning that works across Monospace deployments.

Free vulnerability database: Access detailed information about every Monospace CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Monospace CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Monospace CVEs Free