@strapi/plugin-users-permissions vulnerabilities

Protect your API with a full-authentication process based on JWT

  • latest version

    5.23.4

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    3 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @strapi/plugin-users-permissions package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Replay Attack

    <4.24.2
    • M
    Open Redirect

    <4.24.2
    • H
    Improper Access Control

    >=4.0.0 <4.13.1
    • H
    Denial of Service (DoS)

    <4.12.1
    • C
    Improper Neutralization of Special Elements Used in a Template Engine

    >=4.0.0-next.0 <4.5.6
    • H
    Authentication Bypass

    >=4.0.0-next.0 <4.6.0

    Package versions

    1928 VERSIONS IN TOTAL See all versions
    versionpublisheddirect vulnerabilities
    5.23.410 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.23.34 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.23.23 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.23.127 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.23.020 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.22.013 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.21.06 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.20.030 Jul, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.19.023 Jul, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.18.116 Jul, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L