Description
No description available.
Recommendation
Update the @strapi/strapi package to the latest compatible version. Followings are version details:
- Affected version(s): >= 4.0.0, < 5.37.0
- Patched version(s): 5.37.0
References
Could your website be exposed too?
SmartScanner can check your website for Strapi may leak sensitive data via relational filtering due to lack of query sanitization and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Strapi may leak sensitive user information, user reset password, tokens via content-manager views - @strapi/utils - CVE-2023-36472
- Strapi may leak sensitive user information, user reset password, tokens via content-manager views - CVE-2023-36472
- Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover - @haxtheweb/video-player - CVE-2026-46396
- Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover - CVE-2026-46396
You might also like:
See something that needs correcting? Let us knowUpdated May 21, 2026


