@strapi/plugin-users-permissions
Protect your API with a full-authentication process based on JWT
Moderate Security Advisories for @strapi/plugin-users-permissions in npm Clear Filters
Moderate
3 months ago
Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying
npm
@strapi/plugin-users-permissions
Potential
Moderate
10 months ago
Strapi Password Hashing is Missing Maximum Password Length Validation
npm
@strapi/core
Potential
Potential
Moderate
about 2 years ago
@strapi/plugin-upload has a Denial-of-Service via Improper Exception Handling
npm
@strapi/plugin-upload
Potential
Moderate
almost 3 years ago
Strapi may leak sensitive user information, user reset password, tokens via content-manager views
npm
@strapi/utils, @strapi/admin, @strapi/plugin-content-manager
Potential
Moderate
about 3 years ago
Making all attributes on a content-type public without noticing it
npm
@strapi/database, @strapi/utils, @strapi/strapi
Moderate
over 3 years ago
Strapi does not verify the access or ID tokens issued during the OAuth flow
npm
@strapi/plugin-users-permissions
Potential
Potential
Potential