Strapi is a headless content-management system and API-development platform with a modestly sized but prominently deployed footprint, particularly among modern web and mobile applications that require flexible, graphQL- or REST-driven backend infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, reflecting the platform's role as an internet-facing application gateway and the appeal of its flaws to security researchers and threat actors. The exposure recurs across the core Strapi product and its Protected Populate functionality through a durable set of weakness classes centered on sensitive-information exposure, unrestricted file uploads, authorization bypass through user-controlled inputs, improper authentication, and cross-site scripting—a pattern characteristic of web frameworks where API access control and input validation are essential boundaries. Defenders should treat Strapi deployments as high-priority for patch management, particularly those exposed to untrusted networks or handling sensitive data, since the recurring authorization and authentication flaws can undermine data isolation and access controls at the application layer. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Strapi over time
Signals from CVEs in this vendor scope (41 CVEs).
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18818CRITICAL strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js. | Nov 7, 2019 | 9.8 | 94 | NO | YES |
CVE-2023-22621HIGH Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the | Apr 19, 2023 | 7.2 | 76 | NO | YES |
CVE-2019-19609HIGH The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize t | Dec 5, 2019 | 7.2 | 65 | NO | YES |
CVE-2023-22893HIGH Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could fo | Apr 19, 2023 | 7.5 | 36 | NO | YES |
CVE-2026-27886HIGH Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering con | May 14, 2026 | 7.5 | 31 | NO | NO |
CVE-2022-32114HIGH An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project document | Jul 13, 2022 | 8.8 | 31 | NO | NO |
CVE-2020-27664CRITICAL admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality. | Oct 22, 2020 | 9.8 | 31 | NO | NO |
CVE-2022-27263CRITICAL An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file. | Apr 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2026-57997MEDIUM Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 t | Jun 29, 2026 | 5.4 | 29 | NO | NO |
CVE-2026-22599HIGH Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnera | May 14, 2026 | 7.2 | 29 | NO | NO |
Signals from CVEs in this vendor scope (41 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Strapi.
Media articles that mention a CVE ID that affects a product developed by Strapi — matched by CVE ID, not by vendor name.