Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

strapi — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in strapi, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of security weaknesses associated with Strapi, an open-source Node.js Headless CMS. It systematically collects reports of vulnerabilities affecting Strapi installations, covering critical and high-severity issues released or disclosed between January 2019 and the present date. By centralizing this data, the resource enables security professionals and developers to efficiently track Strapi vendor advisories, understand the characteristics and impact of specific weakness classes such as broken access control or SQL injection, and look up a product's historical vulnerability record for risk assessment purposes. The content includes details on affected versions, severity ratings, and resolution status, offering a clear view of the security landscape surrounding this popular content management framework. Users can analyze trends over time, compare different vulnerability types, and identify potential exposure based on their current deployment configurations. This structured approach helps teams prioritize patching efforts and maintain the integrity of their digital infrastructure without relying on scattered or incomplete information sources. The aggregation focuses on accuracy and timeliness, ensuring that stakeholders have access to the most relevant and actionable security intelligence regarding Strapi-related threats.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2026-57997 Strapi users-permissions - JWT Algorithm Confusion via Missing Algorithm Configuration CWE-327 4.8 Medium2026-06-29
CVE-2026-27886 Strapi may leak sensitive data via relational filtering due to lack of query sanitization CWE-22--2026-05-14
CVE-2026-22707 Strapi Upload Plugin MIME Validation Bypass via Content API CWE-434--2026-05-14
CVE-2026-22706 Strapi: Password Reset Does Not Revoke Existing Refresh Sessions CWE-613--2026-05-14
CVE-2026-22599 Strapi Vulnerable to SQL Injection in Content Type Builder CWE-89--2026-05-14
CVE-2025-64526 Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying CWE-307--2026-05-14
CVE-2025-53092 Strapi core vulnerable to sensitive data exposure via CORS misconfiguration CWE-200 6.5 Medium2025-10-16
CVE-2025-25298 Missing Maximum Password Length Validation in Strapi Password Hashing CWE-261 8.2AIHighAI2025-10-16
CVE-2024-56143 Strapi Allows Unauthorized Access to Private Fields via parms.lookup CWE-639 8.2 High2025-10-16
CVE-2025-3930 Lack of JWT Expiration after Log Out in Strapi CWE-613 9.1AICriticalAI2025-10-16
CVE-2024-52588 Strapi allows Server-Side Request Forgery in Webhook function CWE-918 4.9 Medium2025-05-29
CVE-2024-34065 @strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass CWE-294 7.1 High2024-06-12
CVE-2024-31217 @strapi/plugin-upload has a Denial-of-Service via Improper Exception Handling CWE-248 5.3 Medium2024-06-12
CVE-2024-29181 @strapi/plugin-content-manager leaks data via relations via the Admin Panel CWE-639 2.3 Low2024-06-12
CVE-2023-39345 Unauthorized Access to Private Fields in User Registration API in strapi CWE-287 7.6 High2023-11-06
CVE-2023-38507 Strapi Improper Rate Limiting vulnerability CWE-770 7.3 High2023-09-15
CVE-2023-37263 Strapi's field level permissions not being respected in relationship title CWE-200 6.8 Medium2023-09-15
CVE-2023-36472 Strapi may leak sensitive user information, user reset password, tokens via content-manager views CWE-200 5.8 Medium2023-09-15
CVE-2023-34235 Leaking sensitive user information still possible by filtering on private with prefix fields CWE-200 8.6 High2023-07-25
CVE-2023-34093 Strapi allows actors to make all attributes on a content-type public without noticing it CWE-200 4.8 Medium2023-07-25
CVE-2022-29894 Strapi 跨站脚本漏洞 4.8 -2022-06-13
CVE-2022-30618 Strapi 安全漏洞 CWE-212 7.5 -2022-05-19
CVE-2022-30617 Strapi 安全漏洞 CWE-212 8.8 -2022-05-19
CVE-2020-8123 strapi 资源管理错误漏洞 CWE-400 3.9 -2020-02-04

All 24 known CVE vulnerabilities affecting strapi with full Chinese analysis, references, and POCs where available.