Keystonejs is a Node.js-based headless CMS and content platform with a relatively narrow product scope but meaningful prominence in the web application ecosystem; its vulnerabilities skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency toward public exploit availability. The recurrent exposure centers on the core Keystone product and clusters around web application attack surfaces, including cross-site scripting, authorization flaws, CSRF weaknesses, and information disclosure, reflecting the authentication and content-handling demands of a CMS platform. Defenders should prioritize updates for this vendor and inventory instances facing untrusted networks; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keystonejs over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15879HIGH CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that | Oct 24, 2017 | 8.8 | 41 | NO | YES |
CVE-2017-16570HIGH KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. In other words, it fails to | Nov 6, 2017 | 8.8 | 38 | NO | YES |
CVE-2022-0087MEDIUM keystone is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Jan 12, 2022 | 6.1 | 33 | NO | YES |
CVE-2022-39382CRITICAL Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/[email protected] || 3.0.1` users that use `NODE_ENV` to trigger security-sensitive functionality in the | Nov 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2017-15878MEDIUM A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature. | Oct 24, 2017 | 6.1 | 31 | NO | YES |
CVE-2022-39322CRITICAL @keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multis | Oct 25, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-29354CRITICAL An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file. | May 16, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-32624MEDIUM Keystone 5 is an open source CMS platform to build Node.js applications. This security advisory relates to a newly discovered capability in our query infrastructure to directly or | May 24, 2021 | 5.3 | 19 | NO | NO |
CVE-2015-9240HIGH Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct password is still required t | May 29, 2018 | 7.5 | 19 | NO | NO |
CVE-2017-15881MEDIUM Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the "content brief" or "c | Oct 24, 2017 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keystonejs.
Media articles that mention a CVE ID that affects a product developed by Keystonejs — matched by CVE ID, not by vendor name.