8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether @strapi/plugin-users-permissions is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.1
CVE-2024-34065
@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass
HIGH 7.3
CVE-2023-38507
Strapi Improper Rate Limiting vulnerability
UNKNOWN
CVE-2025-64526
Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying
UNKNOWN
CVE-2026-22706
Strapi: Password Reset Does Not Revoke Existing Refresh Sessions
HIGH 7.6
CVE-2023-39345
Unauthorized Access to Private Fields in User Registration API
UNKNOWN
CVE-2023-22893
Strapi does not verify the access or ID tokens issued during the OAuth flow
CRITICAL 10.0
CVE-2023-22621
Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin
HIGH 8.2
GHSA-xv3q-jrmm-4fxv
Authentication Bypass in @strapi/plugin-users-permissions
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes