Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
Making all attributes on a content-type public without noticing it Moderate
CVE-2023-34093 was published for @strapi/database (npm) Jul 25, 2023
nathan-pichon Credited to nathan-pichon, Marc-Roig, derrickmehaffy, innerdvations, and Convly Marc-Roig Marc-Roig
derrickmehaffy derrickmehaffy innerdvations innerdvations Convly Convly
Strapi may leak sensitive user information, user reset password, tokens via content-manager views Moderate
CVE-2023-36472 was published for @strapi/admin (npm) Sep 13, 2023
Boegie19 Credited to Boegie19, derrickmehaffy, and alexandrebodin derrickmehaffy derrickmehaffy
alexandrebodin alexandrebodin
@strapi/plugin-upload has a Denial-of-Service via Improper Exception Handling Moderate
CVE-2024-31217 was published for @strapi/plugin-upload (npm) Jun 12, 2024
CxDavidepaalte Credited to CxDavidepaalte, derrickmehaffy, Marc-Roig, and alexandrebodin derrickmehaffy derrickmehaffy
Marc-Roig Marc-Roig alexandrebodin alexandrebodin
Strapi's field level permissions not being respected in relationship title Moderate
CVE-2023-37263 was published for @strapi/plugin-content-manager (npm) Sep 13, 2023
Boegie19 Credited to Boegie19, derrickmehaffy, and alexandrebodin derrickmehaffy derrickmehaffy
alexandrebodin alexandrebodin
Strapi allows Server-Side Request Forgery in Webhook function Moderate
CVE-2024-52588 was published for @strapi/admin (npm) May 27, 2025
khoiminhvo32 Credited to khoiminhvo32 and derrickmehaffy derrickmehaffy derrickmehaffy
Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying Moderate
CVE-2025-64526 was published for @strapi/plugin-users-permissions (npm) May 13, 2026
adriatikii Credited to adriatikii and derrickmehaffy derrickmehaffy derrickmehaffy
ProTip! Advisories are also available from the GraphQL API