@strapi/plugin-users-permissions

Protect your API with a full-authentication process based on JWT
Licenses: Unknown

Direct Vulnerabilities

Known vulnerabilities in the @strapi/plugin-users-permissions package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Open Redirect

<4.24.2
  • H
Improper Access Control

>=4.0.0 <4.13.1
  • H
Denial of Service (DoS)

<4.12.1
  • C
Improper Neutralization of Special Elements Used in a Template Engine

>=4.0.0-next.0 <4.5.6
  • H
Authentication Bypass

>=4.0.0-next.0 <4.6.0

Package versions

2282 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
5.44.029 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.43.022 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.42.115 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.42.08 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.41.11 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.41.01 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.40.018 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.39.011 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.38.111 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.38.04 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L