@strapi/strapi
An open source headless CMS solution to create and manage your own API. It provides a powerful dashboard and features to make your life easier. Databases supported: MySQL, MariaDB, PostgreSQL, SQLite
Security Advisories for @strapi/strapi in npm
Critical
3 months ago
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
npm
@strapi/strapi
Potential
High
10 months ago
Strapi core vulnerable to sensitive data exposure via CORS misconfiguration
npm
@strapi/core
Potential
Moderate
10 months ago
Strapi Password Hashing is Missing Maximum Password Length Validation
npm
@strapi/core
Potential
High
10 months ago
Strapi Allows Unauthorized Access to Private Fields via parms.lookup
npm
@strapi/core
High
over 2 years ago
Unauthorized Access to Private Fields in User Registration API
npm
@strapi/strapi, @strapi/plugin-users-permissions
Potential
High
almost 3 years ago
Strapi Improper Rate Limiting vulnerability
npm
@strapi/plugin-users-permissions, @strapi/admin
Potential
Moderate
almost 3 years ago
Strapi may leak sensitive user information, user reset password, tokens via content-manager views
npm
@strapi/utils, @strapi/admin, @strapi/plugin-content-manager
Potential
High
about 3 years ago
Leaking sensitive user information still possible by filtering on private with prefix fields
npm
@strapi/utils, @strapi/database
Moderate
about 3 years ago
Making all attributes on a content-type public without noticing it
npm
@strapi/database, @strapi/utils, @strapi/strapi
Potential
Critical
over 3 years ago
Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin
npm
@strapi/plugin-email, @strapi/plugin-users-permissions
High
over 3 years ago
Strapi leaking sensitive user information by filtering on private fields
npm
@strapi/strapi
High
almost 4 years ago
Strapi mishandles hidden attributes within admin API responses
npm
@strapi/strapi, strapi
High
about 4 years ago
Improper Removal of Sensitive Information Before Storage or Transfer in Strapi
npm
@strapi/strapi, strapi
High
about 4 years ago
Improper Removal of Sensitive Information Before Storage or Transfer in Strapi
npm
@strapi/strapi, strapi
High
about 4 years ago
Insecure password handling vulnerability in Strapi
npm
@strapi/strapi, strapi
Likely fork
Potential
Likely fork
Potential