Catalog / Strapi

Strapi security advisories

All 21 advisories Strapi has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
2121 carry a CVE
critical
4
high
7
medium
6
low
4
Fix in the archive
5of 21 matched to a release
Oldest
18 Apr 20233.4 years ago

16 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2026-27886critical

Leaking sensitive data via relational filtering due to lack of query sanitization

GHSA-rjg2-95x7-8qmxFixed in 5.37.0
CVE-2025-25298low

Weak Password Length Validation

GHSA-2cjv-6wg9-f4f3Fixed in 5.10.3, not held here
CVE-2024-56143high

Unauthorized Access to Private Fields via parms.lookup

GHSA-495j-h493-42q2Fixed in 5.5.2, not held here
CVE-2025-53092high

CORS Misconfiguration Leads to Sensitive Data Exposure

GHSA-9329-mxxw-qwf8Fixed in 5.20.0, not held here
CVE-2024-52588medium

Server - Side Request Forgery in Webhook function

GHSA-v8wj-f5c7-pvxfFixed in 4.25.2, not held here
CVE-2024-29181low

Leaking data via relations via the Admin Panel

GHSA-6j89-frxc-q26mFixed in 4.19.1, not held here
CVE-2024-31217medium

Denial-of-Service via Improper Exception Handling

GHSA-pm9q-xj9p-96pmFixed in 4.22.0, not held here
CVE-2024-34065high

3rd party token leak and authentication bypass

GHSA-wrvh-rcmr-9qfcFixed in 4.24.2, not held here
CVE-2023-39345high

Unauthorized Access to Private Fields in User Registration API

GHSA-gc7p-j5xm-xxh2Fixed in 4.13.1, not held here
CVE-2023-38507high

Improper Rate Limiting

GHSA-24q2-59hm-rh9rFixed in 4.12.1, not held here
CVE-2023-36472medium

Leaking sensitive user information, user reset password, tokens via content-manager views

GHSA-v8gg-4mq2-88q4Fixed in 4.11.7, not held here
CVE-2023-37263low

Field level permissions not being respected in relationship title

GHSA-m284-85mf-cgrcFixed in 4.12.1, not held here
CVE-2023-34235high

Leaking sensitive user information still possible by filtering on private with prefix fields

GHSA-9xg4-3qfm-9w8fFixed in 4.10.8, not held here
CVE-2023-34093medium

Making all attributes on a content-type public via review workflows

GHSA-chmr-rg2f-9jmfFixed in 4.10.8, not held here
CVE-2023-22894critical

Leaking sensitive user information by filtering on private fields

GHSA-jjqf-j4w7-92w8Fixed in 4.8.0, not held here
CVE-2023-22893high

Authentication Bypass for AWS Cognito Login Provider

GHSA-xv3q-jrmm-4fxvFixed in 4.6.0, not held here
CVE-2023-22621critical

SSTI to RCE in the Users-Permissions Plugin

GHSA-2h87-4q2w-v4hfFixed in 4.5.6, not held here