Strapi是法国strapi社区的一套开源的内容管理系统(CMS)。 Strapi 5.0.0版本至5.5.2之前版本存在安全漏洞,该漏洞源于文档服务的查找操作未正确清理私有字段的查询参数,可能导致攻击者通过特制查询访问私有字段。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-53092 | 6.5 MEDIUM | Strapi core vulnerable to sensitive data exposure via CORS misconfiguration |
| CVE-2025-3930 | Lack of JWT Expiration after Log Out in Strapi | |
| CVE-2025-25298 | Missing Maximum Password Length Validation in Strapi Password Hashing |
No comments yet