Known vulnerabilities in strapi.io strapi

Vendor: strapi.io
Website: https://strapi.io/
Total Security Bulletins: 17

Security bulletins (17)

Secuity bulletin Severity Status Published
SB2025052762: SSRF in Strapi Low
Patched
27.05.2025
SB2025032417: Strapi update for axios Medium
Patched Public exploit
24.03.2025
SB2023110622: Improper access control in Strapi Medium
Patched
06.11.2023
SB2023072819: Multiple vulnerabilities in strapi High
Patched
28.07.2023
SB2023050329: Remote code execution in Strapi High
Patched Public exploit
03.05.2023
SB2023050328: Improper Authentication in Strapi High
Patched
03.05.2023
SB2023050327: Information disclosure in Strapi Medium
Patched Public exploit
03.05.2023
SB2023013044: Strapi update for Knex High
Patched
30.01.2023
SB2023011633: Multiple vulnerabilities in strapi High
Patched
16.01.2023
SB2022122821: strapi update for qs Medium
Patched
28.12.2022
SB2022080819: Session Fixation in strapi Medium
Patched
08.08.2022
SB2022051306: Stored cross-site scripting in Strapi Low
Patched
13.05.2022
SB2020102615: Multiple vulnerabilities in Strapi High
Patched
26.10.2020
SB2020061957: Input validation error in strapi.io strapi Medium
Patched
19.06.2020
SB2020020312: Denial of service in Strapi Medium
Patched
03.02.2020
SB2019120606: Remote code execution in Strapi High
Patched Public exploit
06.12.2019
SB2019111505: Weak password recovery mechanism for forgotten password in Strapi High
Patched Public exploit
15.11.2019