11 Total advisories
11 Vulnerabilities
0 Malware
Dependency scanning
Check whether @strapi/strapi is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-27886
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
UNKNOWN
CVE-2025-3930
Strapi is vulnerable to Insufficient Session Expiration
HIGH 8.6
CVE-2024-37818
Strapi Server-Side Request Forgery (SSRF)
MEDIUM 4.6
CVE-2022-32114
Strapi 4.1.12 Cross-site Scripting via crafted file
HIGH 7.6
CVE-2023-39345
Unauthorized Access to Private Fields in User Registration API
MEDIUM 4.8
CVE-2023-34093
Making all attributes on a content-type public without noticing it
HIGH 7.5
CVE-2023-22894
Strapi leaking sensitive user information by filtering on private fields
HIGH 8.8
CVE-2022-31367
Strapi mishandles hidden attributes within admin API responses
HIGH 7.5
CVE-2022-30618
Improper Removal of Sensitive Information Before Storage or Transfer in Strapi
HIGH 8.8
CVE-2022-30617
Improper Removal of Sensitive Information Before Storage or Transfer in Strapi
HIGH 7.5
CVE-2021-46440
Insecure password handling vulnerability in Strapi
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes