@strapi/strapi

An open source headless CMS solution to create and manage your own API. It provides a powerful dashboard and features to make your life easier. Databases supported: MySQL, MariaDB, PostgreSQL, SQLite
Licenses: Unknown

Direct Vulnerabilities

Known vulnerabilities in the @strapi/strapi package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • C
Improper Neutralization of Special Elements in Data Query Logic

>=4.0.0 <5.37.0
  • H
Improper Access Control

>=4.0.0 <4.13.1
  • M
Information Exposure

<4.10.8
  • H
Access Restriction Bypass

>=4.0.0-next.0 <4.5.6
  • H
Information Exposure

>=4.0.0-next.0 <4.8.0
  • M
Improper Input Validation

>=4.0.0-next.0 <4.1.10
  • L
Cross-site Scripting (XSS)

>=4.0.0-next.0 <4.0.0

Package versions

2299 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
5.46.013 May, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.45.111 May, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.45.06 May, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.44.029 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.43.022 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.42.115 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.42.08 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.41.11 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.41.01 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.40.018 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L