13 Total advisories
13 Vulnerabilities
0 Malware
Dependency scanning
Check whether strapi is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.2
GHSA-49vv-6q7q-w5cf
Duplicate Advisory: OS Command Injection in Strapi
HIGH 7.2
CVE-2019-19609
Command Injection in strapi
HIGH 8.8
CVE-2022-31367
Strapi mishandles hidden attributes within admin API responses
HIGH 7.5
CVE-2022-30618
Improper Removal of Sensitive Information Before Storage or Transfer in Strapi
HIGH 8.8
CVE-2022-30617
Improper Removal of Sensitive Information Before Storage or Transfer in Strapi
MEDIUM 4.8
CVE-2022-29894
Cross-site Scripting in Strapi
CRITICAL 9.8
CVE-2022-27263
Unrestricted Upload of File with Dangerous Type in Strapi
MEDIUM 6.1
CVE-2022-0764
Command injection in strapi
HIGH 7.5
CVE-2021-46440
Insecure password handling vulnerability in Strapi
HIGH 8.1
CVE-2021-28128
Weak Password Recovery Mechanism for Forgotten Password in Strapi
CRITICAL 9.8
CVE-2020-27664
Authorization bypass in Strapi
MEDIUM 6.5
CVE-2020-13961
Improper Input Validation in strapi
CRITICAL 9.8
CVE-2019-18818
Strapi allows unauthenticated attacker to reset admin password without valid reset token
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes