{"api_version":"v1","generated_at":"2026-10-08T04:50:00+00:00","product":{"cve_count":20,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-strapi-strapi-88f633357f32","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/strapi","name":"Strapi","next_cursor":null,"observations":[{"affected":"strapi: 4.0.0 \u2264 4.26.2, 5.0.0 < 5.48.1","affected_versions_present":true,"cve_id":"CVE-2026-90561","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90561","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T14:21:46.210Z","patch_url":"","primary_source":"","published":"2026-09-13T10:45:35.988Z"},{"affected":"< 5.7.0","affected_versions_present":true,"cve_id":"CVE-2026-57997","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-57997","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-09T18:48:34.051Z","patch_url":"https://github.com/strapi/strapi/pull/26752","primary_source":"","published":"2026-06-29T21:16:35.174Z"},{"affected":">= 4.0.0, < 5.37.0","affected_versions_present":true,"cve_id":"CVE-2026-27886","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27886","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T19:50:58.218Z","patch_url":"","primary_source":"","published":"2026-05-14T18:43:04.844Z"},{"affected":"< 5.33.3","affected_versions_present":true,"cve_id":"CVE-2026-22707","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22707","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T19:40:11.102Z","patch_url":"","primary_source":"","published":"2026-05-14T18:40:22.080Z"},{"affected":"< 5.33.3","affected_versions_present":true,"cve_id":"CVE-2026-22706","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22706","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-15T14:52:06.866Z","patch_url":"","primary_source":"","published":"2026-05-14T18:38:26.745Z"},{"affected":">= 5.0.0, < 5.33.2; >= 4.0.0, < 4.26.1","affected_versions_present":true,"cve_id":"CVE-2026-22599","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22599","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-14T19:45:29.894Z","patch_url":"https://github.com/strapi/strapi/releases/tag/v4.26.1","primary_source":"","published":"2026-05-14T18:35:57.661Z"},{"affected":"< 5.45.0","affected_versions_present":true,"cve_id":"CVE-2025-64526","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64526","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-16T00:49:25.996Z","patch_url":"https://github.com/strapi/strapi/commit/5e0d243cba9830e6f791de6a94798bcde51468db","primary_source":"","published":"2026-05-14T18:32:01.998Z"},{"affected":"< 5.20.0","affected_versions_present":true,"cve_id":"CVE-2025-53092","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-53092","fixed":"5.20.0.","last_modified":"2025-10-16T18:13:08.618Z","patch_url":"https://github.com/strapi/strapi/security/advisories/GHSA-9329-mxxw-qwf8","primary_source":"","published":"2025-10-16T16:29:35.246Z"},{"affected":"< 5.10.3","affected_versions_present":true,"cve_id":"CVE-2025-25298","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-25298","fixed":"5.10.3.","last_modified":"2025-10-16T18:12:49.837Z","patch_url":"https://github.com/strapi/strapi/commit/41f8cdf116f7f464dae7d591e52d88f7bfa4b7cb","primary_source":"","published":"2025-10-16T16:21:45.585Z"},{"affected":">= 5.0.0, < 5.5.2","affected_versions_present":true,"cve_id":"CVE-2024-56143","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-56143","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-16T17:54:24.103Z","patch_url":"https://github.com/strapi/strapi/commit/0c6e0953ae1e62afae9329de7ae6d6a5e21b95b8","primary_source":"","published":"2025-10-16T16:07:30.996Z"},{"affected":"< 5.24.1","affected_versions_present":true,"cve_id":"CVE-2025-3930","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-3930","fixed":"5.24.1.","last_modified":"2025-10-22T06:59:29.045Z","patch_url":"https://cert.pl/en/posts/2025/06/CVE-2025-3930","primary_source":"","published":"2025-10-16T10:43:21.382Z"},{"affected":"< 4.25.2","affected_versions_present":true,"cve_id":"CVE-2024-52588","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-52588","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-29T13:44:40.528Z","patch_url":"","primary_source":"","published":"2025-05-29T09:02:15.144Z"},{"affected":"< 4.24.2","affected_versions_present":true,"cve_id":"CVE-2024-34065","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-34065","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-02T02:42:59.898Z","patch_url":"","primary_source":"","published":"2024-06-12T14:54:46.045Z"},{"affected":"< 4.22.0","affected_versions_present":true,"cve_id":"CVE-2024-31217","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-31217","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T01:46:04.759Z","patch_url":"https://github.com/strapi/strapi/commit/a0da7e73e1496d835fe71a2febb14f70170135c7","primary_source":"","published":"2024-06-12T14:50:37.999Z"},{"affected":"< 4.19.1","affected_versions_present":true,"cve_id":"CVE-2024-29181","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-29181","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T01:10:54.079Z","patch_url":"https://github.com/strapi/strapi/commit/e1dfd4d9f1cab25cf6da3614c1975e4e508e01c6","primary_source":"","published":"2024-06-12T14:46:04.902Z"},{"affected":">= 4.0.0, < 4.13.1","affected_versions_present":true,"cve_id":"CVE-2023-39345","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-39345","fixed":"4.13.1.","last_modified":"2024-09-04T19:31:38.962Z","patch_url":"https://github.com/strapi/strapi/security/advisories/GHSA-gc7p-j5xm-xxh2","primary_source":"","published":"2023-11-06T18:26:20.324Z"},{"affected":"< 4.12.1","affected_versions_present":true,"cve_id":"CVE-2023-38507","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-38507","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-25T18:05:58.465Z","patch_url":"","primary_source":"","published":"2023-09-15T19:15:06.391Z"},{"affected":"< 4.12.1","affected_versions_present":true,"cve_id":"CVE-2023-37263","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-37263","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-25T14:58:52.828Z","patch_url":"","primary_source":"","published":"2023-09-15T18:57:09.623Z"},{"affected":"< 4.11.7","affected_versions_present":true,"cve_id":"CVE-2023-36472","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-36472","fixed":"4.11.7.","last_modified":"2024-09-25T15:00:46.751Z","patch_url":"https://github.com/strapi/strapi/security/advisories/GHSA-v8gg-4mq2-88q4","primary_source":"","published":"2023-09-15T18:54:34.072Z"},{"affected":"< 4.10.8","affected_versions_present":true,"cve_id":"CVE-2023-34235","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-34235","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-10-03T20:02:58.764Z","patch_url":"","primary_source":"","published":"2023-07-25T17:24:19.864Z"},{"affected":"< 4.10.8","affected_versions_present":true,"cve_id":"CVE-2023-34093","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-34093","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-10-03T20:03:57.103Z","patch_url":"https://github.com/strapi/strapi/commit/2fa8f30371bfd1db44c15e5747860ee5789096de","primary_source":"","published":"2023-07-25T14:54:42.434Z"},{"affected":"v3.x.x versions and earlier","affected_versions_present":true,"cve_id":"CVE-2022-29894","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-29894","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-03T06:33:42.954Z","patch_url":"","primary_source":"","published":"2022-06-13T04:50:35.000Z"},{"affected":"< 3.6.10; < 4.1.10","affected_versions_present":true,"cve_id":"CVE-2022-30618","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-30618","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-03T06:56:13.298Z","patch_url":"","primary_source":"","published":"2022-05-19T17:08:47.000Z"},{"affected":"< 3.6.9; ! 4.0.0; < 4.0.0-beta.16","affected_versions_present":true,"cve_id":"CVE-2022-30617","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-30617","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-03T06:56:12.964Z","patch_url":"","primary_source":"","published":"2022-05-19T17:07:36.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"Strapi"}}
