OSS Support Hub / CMS

Node.js CMS NOASSERTION Latest: v11.17.4

Directus

Open source data platform wrapping any SQL database with a real-time REST and GraphQL API

Project Health at a Glance

Live data from GitHub and npm, updated daily.

โญ
35.7K+3
GitHub Stars
๐Ÿ“ฆ
v11.17.4
Latest Release ยท 15 days ago
๐Ÿ”„
9d
Avg. Release Cadence
๐Ÿ›
402
Open Issues
๐Ÿ“…
Yesterday
Last Commit
โฌ‡๏ธ
13.8K
Weekly Downloads
๐Ÿ”’
10
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Directus affected by VM2 sandbox escape vulnerability

Published: 2023-09-15 Fixed in: 10.6.0

Session Token in URL in directus

Published: 2024-03-12 Fixed in: 10.10.0

Directus has open redirect in SAML

Published: 2026-01-06 Fixed in: 11.14.0

Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries

Published: 2026-04-04 Fixed in: 11.17.0

Directus: Path Traversal and Broken Access Control in File Management API

Published: 2026-04-04 Fixed in: 11.17.0

Directus has an insecure object reference via PATH presets

Published: 2024-08-27 Fixed in: 10.13.2

Directus API vulnerable to denial of service

Published: 2023-04-04 Fixed in: 2.2.1

directus vulnerable to HTML Injection in Password Reset email to custom Reset URL

Published: 2023-03-07 Fixed in: 9.23.0

Suspended Directus user can continue to use session token to access API

Published: 2025-03-26 Fixed in: 11.5.0

Server-Side Request Forgery in Directus

Published: 2022-06-23 Fixed in: 9.7.0

Alternatives to Directus

Other CMS projects in the Node.js ecosystem worth evaluating.

Support Options for Directus

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Directus โ€” without relying on volunteer maintainers.

Talk to an Expert โ†’