Monospace maintains Directus, a widely adopted open-source headless CMS and API platform that abstracts database access and content management across diverse applications and deployments. The vendor's vulnerability profile concentrates on data-exposure and access-control weaknesses—including sensitive information disclosure, improper access restrictions, and incorrect authorization logic—reflecting the authentication and permission-boundary demands inherent to a system managing user roles and content visibility. The exposure pattern centers on a single product line rather than a broad portfolio, yet the platform's prevalence in the content-management landscape elevates the relevance of these disclosures to a broad defender audience. Defenders should prioritize patching this vendor's releases, particularly those addressing access-control and data-visibility boundaries, since misconfigurations or flaws in permission enforcement can expose sensitive content across dependent applications. Current CVE volume, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Monospace over time
Signals from CVEs in this vendor scope (54 CVEs).
54 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35408CRITICAL Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy ( | Apr 6, 2026 | 9.3 | 34 | NO | NO |
CVE-2026-35442HIGH Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields with the conceal special type in | Apr 6, 2026 | 8.1 | 31 | NO | NO |
CVE-2022-26969CRITICAL In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true. | Dec 26, 2022 | 9.8 | 30 | NO | NO |
CVE-2026-39942HIGH Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter. | Apr 9, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-35412HIGH Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tus) allows any authenticated use | Apr 6, 2026 | 8.1 | 29 | NO | NO |
CVE-2026-35409HIGH Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request Forgery (SSRF) protection bypass has been identified and fi | Apr 6, 2026 | 7.7 | 29 | NO | NO |
CVE-2025-55746HIGH Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an u | Aug 20, 2025 | 7.5 | 28 | NO | NO |
CVE-2026-35441MEDIUM Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql/system) did not deduplicate re | Apr 6, 2026 | 6.5 | 26 | NO | NO |
CVE-2024-27295HIGH Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Directus backend allows attackers to receive a password reset e | Mar 1, 2024 | 8.2 | 25 | NO | NO |
CVE-2026-35410MEDIUM Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login redirection logic. The isLogin | Apr 6, 2026 | 6.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (54 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Monospace.
Media articles that mention a CVE ID that affects a product developed by Monospace — matched by CVE ID, not by vendor name.