Vulnerability
Published 2026-10-08
Verified 2026-10-08

Strapi Strapi (CVE-2023-22894)

Strapi Cleartext Storage of Sensitive Information Vulnerability. Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

Product
Strapi Strapi
Exploited in Australia?
unknown

Primary: NVD · Vendor: CISA KEV · CVE: CVE-2023-22894, CVE-2023-22621

vulnerabilities