Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Strapi

First CVE: Nov 7, 2019Active for: 7 yearsTotal CVEs: 41
57.1
VTI Score
TOP TARGET

Strapi is a headless content-management system and API-development platform with a modestly sized but prominently deployed footprint, particularly among modern web and mobile applications that require flexible, graphQL- or REST-driven backend infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, reflecting the platform's role as an internet-facing application gateway and the appeal of its flaws to security researchers and threat actors. The exposure recurs across the core Strapi product and its Protected Populate functionality through a durable set of weakness classes centered on sensitive-information exposure, unrestricted file uploads, authorization bypass through user-controlled inputs, improper authentication, and cross-site scripting—a pattern characteristic of web frameworks where API access control and input validation are essential boundaries. Defenders should treat Strapi deployments as high-priority for patch management, particularly those exposed to untrusted networks or handling sensitive data, since the recurring authorization and authentication flaws can undermine data isolation and access controls at the application layer. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
41
Total CVEs
More Total CVEs than 98% of tracked vendors
2.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Strapi over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 7, 2019
6 years ago
Most Recent CVE
Jun 29, 2026
25 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-18818CRITICAL
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
Nov 7, 20199.894NOYES
CVE-2023-22621HIGH
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the
Apr 19, 20237.276NOYES
CVE-2019-19609HIGH
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize t
Dec 5, 20197.265NOYES
CVE-2023-22893HIGH
Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could fo
Apr 19, 20237.536NOYES
CVE-2026-27886HIGH
Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering con
May 14, 20267.531NONO
CVE-2022-32114HIGH
An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project document
Jul 13, 20228.831NONO
CVE-2020-27664CRITICAL
admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.
Oct 22, 20209.831NONO
CVE-2022-27263CRITICAL
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.
Apr 12, 20229.830NONO
CVE-2026-57997MEDIUM
Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 t
Jun 29, 20265.429NONO
CVE-2026-22599HIGH
Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnera
May 14, 20267.229NONO
View all 41 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products41 CVEs
39%
46%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.4%)
Network40 (97.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (95.1%)
High2 (4.9%)
Unknown0 (0.0%)
User Interaction
None35 (85.4%)
Unknown0 (0.0%)
Required6 (14.6%)
Privileges Required
Low13 (31.7%)
High9 (22.0%)
None19 (46.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (41 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.4% of CVEs· 97th percentile
Nuclei
3 CVEs
7.3% of CVEs· 96th percentile
ExploitDB
2 CVEs
4.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Strapi.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Strapi — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Strapi's Products

View all 8 CNAs →

Top CWEs