npm package intelligence

@strapi/strapi Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the npm package @strapi/strapi, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting @strapi/strapi
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
@strapi/strapi KEVs with sensor-observed exploitation activity

Review @strapi/strapi exploitation against the versions you run

The single exploited @strapi/strapi vulnerability tracked by Previdian is also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested @strapi/strapi vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2023-22894

Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The...

In CISA 08 Oct 2026

Recurring weakness patterns

Cleartext Storage of Sensitive Information accounts for mapped occurrences across this @strapi/strapi KEV portfolio.

Browse all KEVs →