SecAlerts
s

strapi

Security Risk Profile

39
/100
low

Security Risk Score

Comprehensive risk assessment based on 42 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from November 7, 2019 to present

42
Total CVEs
25
Critical+High
1
Exploited
8
Unpatched

Threat Assessment

Avg CVSS
7.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
8
Critical/High
Risk Level
39/100
low
⚠️ 1 Active Exploits🆕 1Fresh (<7d)📈 2 in Last 30 Days

Severity Distribution

Critical
10
High
15
Medium
15
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
Infoleak
6
2
XSS
5
3
Malicious File Upload
3
4
SQL Injection
3
5
OS Command Injection
2

Most Affected Products

1. Strapi Strapi236
2. Strapi Strapi Node.js105
3. npm/@strapi/plugin-users-permissions7
4. npm/@strapi/strapi6
5. npm/@strapi/admin4

Recent Vulnerabilities

See more →

Monitor strapi in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

strapi Security Vulnerabilities & Risk Score | 42 CVEs | SecAlerts - SecAlerts