SecAlerts
s

strapi

Security Risk Profile

47
/100
medium

Security Risk Score

Comprehensive risk assessment based on 41 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from November 7, 2019 to present

41
Total CVEs
25
Critical+High
0
Exploited
8
Unpatched

Threat Assessment

Avg CVSS
7.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
8
Critical/High
Risk Level
47/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
10
High
15
Medium
14
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
Infoleak
6
2
XSS
5
3
Malicious File Upload
3
4
SQL Injection
3
5
OS Command Injection
2

Most Affected Products

1. Strapi Strapi234
2. Strapi Strapi Node.js105
3. npm/@strapi/plugin-users-permissions7
4. npm/@strapi/strapi6
5. npm/@strapi/admin4

Recent Vulnerabilities

See more →

Monitor strapi in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

strapi Security Vulnerabilities & Risk Score | 41 CVEs | SecAlerts - SecAlerts