Vulnerabilities (CVE)

Filtered by vendor Strapi Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-18818 1 Strapi 1 Strapi 2022-02-20 7.5 HIGH 9.8 CRITICAL
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
CVE-2020-27664 1 Strapi 1 Strapi 2020-10-27 7.5 HIGH 9.8 CRITICAL
admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.