@strapi/strapi

An open source headless CMS solution to create and manage your own API. It provides a powerful dashboard and features to make your life easier. Databases supported: MySQL, MariaDB, PostgreSQL, SQLite
Licenses: Unknown

Direct Vulnerabilities

Known vulnerabilities in the @strapi/strapi package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Improper Access Control

>=4.0.0 <4.13.1
  • M
Information Exposure

<4.10.8
  • H
Access Restriction Bypass

>=4.0.0-next.0 <4.5.6
  • H
Information Exposure

>=4.0.0-next.0 <4.8.0
  • M
Improper Input Validation

>=4.0.0-next.0 <4.1.10
  • L
Cross-site Scripting (XSS)

>=4.0.0-next.0 <4.0.0

Package versions

2211 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
5.41.11 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.41.01 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.40.018 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.39.011 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.38.111 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.38.04 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.37.126 Feb, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.37.026 Feb, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.36.118 Feb, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.36.011 Feb, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L