Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Monospace

First CVE: Aug 19, 2022Active for: 4 yearsTotal CVEs: 54
22.6
VTI Score
Low

Monospace maintains Directus, a widely adopted open-source headless CMS and API platform that abstracts database access and content management across diverse applications and deployments. The vendor's vulnerability profile concentrates on data-exposure and access-control weaknesses—including sensitive information disclosure, improper access restrictions, and incorrect authorization logic—reflecting the authentication and permission-boundary demands inherent to a system managing user roles and content visibility. The exposure pattern centers on a single product line rather than a broad portfolio, yet the platform's prevalence in the content-management landscape elevates the relevance of these disclosures to a broad defender audience. Defenders should prioritize patching this vendor's releases, particularly those addressing access-control and data-visibility boundaries, since misconfigurations or flaws in permission enforcement can expose sensitive content across dependent applications. Current CVE volume, severity distribution, and exploitation status are shown alongside this summary.

FAUCET AI Generated
54
Total CVEs
More Total CVEs than 99% of tracked vendors
10.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Monospace over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 19, 2022
3 years ago
Most Recent CVE
Apr 9, 2026
107 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (54 CVEs).

54 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-35408CRITICAL
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy (
Apr 6, 20269.334NONO
CVE-2026-35442HIGH
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields with the conceal special type in
Apr 6, 20268.131NONO
CVE-2022-26969CRITICAL
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
Dec 26, 20229.830NONO
CVE-2026-39942HIGH
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter.
Apr 9, 20268.829NONO
CVE-2026-35412HIGH
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tus) allows any authenticated use
Apr 6, 20268.129NONO
CVE-2026-35409HIGH
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request Forgery (SSRF) protection bypass has been identified and fi
Apr 6, 20267.729NONO
CVE-2025-55746HIGH
Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an u
Aug 20, 20257.528NONO
CVE-2026-35441MEDIUM
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql/system) did not deduplicate re
Apr 6, 20266.526NONO
CVE-2024-27295HIGH
Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Directus backend allows attackers to receive a password reset e
Mar 1, 20248.225NONO
CVE-2026-35410MEDIUM
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login redirection logic. The isLogin
Apr 6, 20266.124NONO
View all 54 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products54 CVEs
74%
20%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (7.4%)
Network50 (92.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low53 (98.1%)
High1 (1.9%)
Unknown0 (0.0%)
User Interaction
None40 (74.1%)
Unknown0 (0.0%)
Required14 (25.9%)
Privileges Required
Low26 (48.1%)
High5 (9.3%)
None23 (42.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (54 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Monospace.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Monospace — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Monospace's Products

View all 3 CNAs →

Top CWEs