OSS Support Hub / CMS

Node.js CMS NOASSERTION Latest: v12.0.2

Directus

Open source data platform wrapping any SQL database with a real-time REST and GraphQL API

Project Health at a Glance

Live data from GitHub and npm, updated daily.

36.4K+327
GitHub Stars
📦
v12.0.2
Latest Release · 17 days ago
🔄
9d
Avg. Release Cadence
🐛
386
Open Issues
📅
Today
Last Commit
⬇️
25.0K
Weekly Downloads
🔒
10
Active CVEs

Data last fetched: 2026-06-29

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Directus affected by VM2 sandbox escape vulnerability

Published: 2023-09-15 Fixed in: 10.6.0

Session Token in URL in directus

Published: 2024-03-12 Fixed in: 10.10.0

Directus has open redirect in SAML

Published: 2026-01-06 Fixed in: 11.14.0

Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries

Published: 2026-04-04 Fixed in: 11.17.0

Directus: Path Traversal and Broken Access Control in File Management API

Published: 2026-04-04 Fixed in: 11.17.0

Directus has an insecure object reference via PATH presets

Published: 2024-08-27 Fixed in: 10.13.2

Directus API vulnerable to denial of service

Published: 2023-04-04 Fixed in: 2.2.1

directus vulnerable to HTML Injection in Password Reset email to custom Reset URL

Published: 2023-03-07 Fixed in: 9.23.0

Suspended Directus user can continue to use session token to access API

Published: 2025-03-26 Fixed in: 11.5.0

Server-Side Request Forgery in Directus

Published: 2022-06-23 Fixed in: 9.7.0

Alternatives to Directus

Other CMS projects in the Node.js ecosystem worth evaluating.

Support Options for Directus

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Directus — without relying on volunteer maintainers.