Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Strapi — Vulnerabilities & Security Advisories 25

All 25 CVE vulnerabilities found in Strapi, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for the Strapi product family, focusing on software weaknesses affecting its core components. It collects data on various vulnerability types, including remote code execution, authentication bypass, and input validation errors, covering the historical period from the product's initial release through the most recent advisory updates. Readers can use this resource to track Strapi’s security advisories, understand specific weakness classes impacting the CMS, and review the complete vulnerability history for version-specific risk assessment. The aggregation provides a structured view of how security flaws have evolved over time, enabling security teams to identify patterns, prioritize patching, and monitor emerging threats without needing to parse individual database entries. By centralizing this information, the page supports efficient vulnerability management and helps organizations maintain an up-to-date understanding of Strapi’s security posture across different release cycles.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-90561 Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG CWE-79 8.7 High 2026-09-13
CVE-2026-57997 Strapi users-permissions - JWT Algorithm Confusion via Missing Algorithm Configuration CWE-327 4.8 Medium 2026-06-29
CVE-2026-27886 Strapi may leak sensitive data via relational filtering due to lack of query sanitization CWE-22 - - 2026-05-14
CVE-2026-22707 Strapi Upload Plugin MIME Validation Bypass via Content API CWE-434 - - 2026-05-14
CVE-2026-22706 Strapi: Password Reset Does Not Revoke Existing Refresh Sessions CWE-613 - - 2026-05-14
CVE-2026-22599 Strapi Vulnerable to SQL Injection in Content Type Builder CWE-89 - - 2026-05-14
CVE-2025-64526 Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying CWE-307 - - 2026-05-14
CVE-2025-53092 Strapi core vulnerable to sensitive data exposure via CORS misconfiguration CWE-200 6.5 Medium 2025-10-16
CVE-2025-25298 Missing Maximum Password Length Validation in Strapi Password Hashing CWE-261 8.2AI High AI 2025-10-16
CVE-2024-56143 Strapi Allows Unauthorized Access to Private Fields via parms.lookup CWE-639 8.2 High 2025-10-16
CVE-2025-3930 Lack of JWT Expiration after Log Out in Strapi CWE-613 9.1AI Critical AI 2025-10-16
CVE-2024-52588 Strapi allows Server-Side Request Forgery in Webhook function CWE-918 4.9 Medium 2025-05-29
CVE-2024-34065 @strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass CWE-294 7.1 High 2024-06-12
CVE-2024-31217 @strapi/plugin-upload has a Denial-of-Service via Improper Exception Handling CWE-248 5.3 Medium 2024-06-12
CVE-2024-29181 @strapi/plugin-content-manager leaks data via relations via the Admin Panel CWE-639 2.3 Low 2024-06-12
CVE-2023-39345 Unauthorized Access to Private Fields in User Registration API in strapi CWE-287 7.6 High 2023-11-06
CVE-2023-38507 Strapi Improper Rate Limiting vulnerability CWE-770 7.3 High 2023-09-15
CVE-2023-37263 Strapi's field level permissions not being respected in relationship title CWE-200 6.8 Medium 2023-09-15
CVE-2023-36472 Strapi may leak sensitive user information, user reset password, tokens via content-manager views CWE-200 5.8 Medium 2023-09-15
CVE-2023-34235 Leaking sensitive user information still possible by filtering on private with prefix fields CWE-200 8.6 High 2023-07-25
CVE-2023-34093 Strapi allows actors to make all attributes on a content-type public without noticing it CWE-200 4.8 Medium 2023-07-25
CVE-2022-29894 Strapi 跨站脚本漏洞 4.8 - 2022-06-13
CVE-2022-30618 Strapi 安全漏洞 CWE-212 7.5 - 2022-05-19
CVE-2022-30617 Strapi 安全漏洞 CWE-212 8.8 - 2022-05-19
CVE-2020-8123 strapi 资源管理错误漏洞 CWE-400 3.9 - 2020-02-04

All 25 known CVE vulnerabilities affecting Strapi with full Chinese analysis, references, and POCs where available.