Directus

Vendor:

First CVE: Aug 19, 2022 · Active for 3 years

54
Total CVEs
More Total CVEs than 98% of tracked products
10.8
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Directus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 19, 2022
3 years ago
Most Recent CVE
Apr 9, 2026
106 days ago

CVE Severity & Scoring

Directus54 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local4 (7.4%)
Network50 (92.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low53 (98.1%)
High1 (1.9%)
Unknown0 (0.0%)
User Interaction
None40 (74.1%)
Unknown0 (0.0%)
Required14 (25.9%)
Privileges Required
Low26 (48.1%)
High5 (9.3%)
None23 (42.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (54 CVEs).

54 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy (
Apr 6, 20269.332NONO
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
Dec 26, 20229.830NONO
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter.
Apr 9, 20268.829NONO
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields with the conceal special type in
Apr 6, 20268.128NONO
Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an u
Aug 20, 20257.528NONO
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tus) allows any authenticated use
Apr 6, 20268.127NONO
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request Forgery (SSRF) protection bypass has been identified and fi
Apr 6, 20267.726NONO
Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Directus backend allows attackers to receive a password reset e
Mar 1, 20248.225NONO
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.5.0, when a Flow with the "Webhook" trigger and
Mar 26, 20257.524NONO
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql/system) did not deduplicate re
Apr 6, 20266.523NONO

Exploit Exposure

Signals from CVEs in this product scope (54 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (54 CVEs).

Media Mentions

Signals from CVEs in this product scope (54 CVEs).

Top CNAs Publishing CVEs For Directus

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0.015.30.4%00
2.2.016.51.1%00
10.13.024.80.3%00