Protect your API with a full-authentication process based on JWT
89%
Total Score
100
65
91
100
0
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-493176 New @strapi/plugin-users-permissions is vulnerable to Use of a Broken or Risky Cryptographic Algorithm in versions 0.0.1 - 5.49.0. | 0.0.1 - 5.49.0 | Medium |
CVE-2025-64526 @strapi/plugin-users-permissions is vulnerable to Improper Restriction of Excessive Authentication Attempts in versions 0.0.0 - 5.44.0. | 0.0.0 - 5.44.0 | Medium |
CVE-2024-34065 @strapi/plugin-users-permissions is vulnerable to Authentication Bypass by Capture-replay in versions 0.0.0 - 4.24.2. | 0.0.0 - 4.24.2 | High |
CVE-2023-39345 @strapi/plugin-users-permissions is vulnerable to Improper Authentication in versions 4.0.0 - 4.13.1. | 4.0.0 - 4.13.1 | High |
CVE-2023-22893 @strapi/plugin-users-permissions is vulnerable to Security Vulnerability in versions 3.2.1 - 4.6.0. | 3.2.1 - 4.6.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
koa Version 2.16.4 | — | — |
yup Version 0.32.9 | — | — |
zod Version 3.25.76 | — | — |
immer Version 9.0.21 | — | — |
formik Version 2.4.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant