Rangerstudio maintains Directus, a headless CMS and API platform that has attracted vulnerability research attention despite a narrow product scope, with its modestly represented but notable presence in the landscape reflecting the platform's deployment in content-management and API-layer roles. The vendor's vulnerabilities skew toward serious outcomes, with an elevated share reaching critical severity, and concentrate in recurring weakness classes including cross-site scripting, unrestricted file uploads, cleartext storage of sensitive data, and exposure of sensitive information—issues characteristic of web application input handling, file management, and data-protection layers. Defenders should prioritize Directus deployments in their inventory and monitor releases closely, particularly for internet-reachable instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rangerstudio over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13983CRITICAL Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php. | Jul 19, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-10723CRITICAL Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql. | May 5, 2018 | 9.8 | 29 | NO | NO |
CVE-2021-29641HIGH Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include the ability to upload a .php file to the main upload dir | Apr 7, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-13984HIGH Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a direct link to each uploaded file, accessible by unauthentic | Jul 19, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-13980HIGH In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals remote code execution with nginx. | Jul 19, 2019 | 8.8 | 27 | NO | NO |
CVE-2021-26594HIGH In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects pr | Feb 23, 2021 | 8.8 | 26 | NO | NO |
CVE-2019-13979HIGH In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution. | Jul 19, 2019 | 8.8 | 26 | NO | NO |
CVE-2021-26593HIGH In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they get in response a lot of information about the user (such as | Feb 23, 2021 | 7.5 | 23 | NO | NO |
CVE-2022-24814MEDIUM Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized JavaScript (JS) can be executed by inserting an iframe into th | Apr 4, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-23080MEDIUM In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perfor | Jun 22, 2022 | 5.0 | 20 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rangerstudio.
Media articles that mention a CVE ID that affects a product developed by Rangerstudio — matched by CVE ID, not by vendor name.