Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

keystonejs — Vulnerabilities & Security Advisories 10

Browse all 10 CVE security advisories affecting keystonejs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

KeystoneJS is an open-source Node.js CMS and headless framework for building web applications and content management systems. Historically, it has been vulnerable to classes including remote code execution, cross-site scripting, and privilege escalation, with eight CVEs recorded. Security characteristics include its express-based architecture and customizable admin UI. Notable incidents include a 2021 RCE vulnerability (CVE-2021-22883) allowing arbitrary code execution through crafted API requests, and a 2019 XSS flaw (CVE-2019-5429) in the admin panel. The framework requires careful configuration to mitigate risks, particularly around user input handling and access control.

Found 1 results / 10 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2021-32624 Private Field data leak — keystone-5 CWE-200 7.5 High 2021-05-24

This page lists every published CVE security advisory associated with keystonejs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.