Core of Strapi
83%
Total Score
63
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10088 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @strapi/core is vulnerable to Improper Access Control in versions 5.0.0 - 5.33.1 and 4.0.0 - 4.26.0. | 4.0.0 - 4.26.05.0.0 - 5.33.1 | High |
AIKIDO-2026-10066 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @strapi/core is vulnerable to Insufficient Session Expiration in versions 1.0.0 - 5.33.2. | 1.0.0 - 5.33.2 | Low |
CVE-2024-56143 @strapi/core is vulnerable to Authorization Bypass Through User-Controlled Key in versions 5.0.0 - 5.5.2. | 5.0.0 - 5.5.2 | High |
CVE-2025-53092 @strapi/core is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 5.20.0. | 0.0.0 - 5.20.0 | High |
CVE-2025-25298 @strapi/core is vulnerable to Weak Encoding for Password in versions 0.0.0 - 5.10.3. | 0.0.0 - 5.10.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
qs Version 6.14.2 | — | — |
koa Version 2.16.3 | — | — |
ora Version 5.4.1 | — | — |
yup Version 0.32.9 | — | — |
zod Version 3.25.67 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant