Directus
Vendor:
First CVE: May 5, 2018 · Active for 8 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Directus over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2018
8 years ago
Most Recent CVE
Mar 6, 2023
1,236 days ago
CVE Severity & Scoring
Directus11 CVEs
64%
27%
9%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (63.6%)
Unknown0 (0.0%)
Required4 (36.4%)
Privileges Required
Low6 (54.5%)
High0 (0.0%)
None5 (45.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10723CRITICAL Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql. | May 5, 2018 | 9.8 | 29 | NO | NO |
CVE-2021-29641HIGH Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include the ability to upload a .php file to the main upload dir | Apr 7, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-26594HIGH In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects pr | Feb 23, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-26593HIGH In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they get in response a lot of information about the user (such as | Feb 23, 2021 | 7.5 | 23 | NO | NO |
CVE-2022-24814MEDIUM Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized JavaScript (JS) can be executed by inserting an iframe into th | Apr 4, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-23080MEDIUM In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perfor | Jun 22, 2022 | 5.0 | 20 | NO | NO |
CVE-2022-22117MEDIUM In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cross-Site Scripting vulnerability | Jan 10, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-22116MEDIUM In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file upload in media upload functionality. A low privile | Jan 10, 2022 | 5.4 | 20 | NO | NO |
CVE-2023-27474MEDIUM Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed reset URL are vulnerable to an HTML injection attack through t | Mar 6, 2023 | 5.4 | 19 | NO | NO |
CVE-2021-27583MEDIUM In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature. NOTE: This vulnerability only affects products | Feb 23, 2021 | 5.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Directus
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.0 | 3 | 5.3 | 0.7% | 0 | 0 |
| 6.4.9 | 1 | 9.8 | 1.3% | 0 | 0 |