4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether @strapi/admin is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.8
CVE-2023-36472
Strapi may leak sensitive user information, user reset password, tokens via content-manager views
HIGH 7.3
CVE-2023-38507
Strapi Improper Rate Limiting vulnerability
UNKNOWN
CVE-2026-22706
Strapi: Password Reset Does Not Revoke Existing Refresh Sessions
MEDIUM 4.9
CVE-2024-52588
Strapi allows Server-Side Request Forgery in Webhook function
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes