OSS Support Hub / CMS

Node.js CMS NOASSERTION Latest: v5.46.0

Strapi

Leading open source headless CMS — fully customizable, developer-first content platform

Project Health at a Glance

Live data from GitHub and npm, updated daily.

72.2K+5
GitHub Stars
📦
v5.46.0
Latest Release · 2 days ago
🔄
6d
Avg. Release Cadence
🐛
756
Open Issues
📅
Yesterday
Last Commit
⬇️
225.6K
Weekly Downloads
🔒
10
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Strapi mishandles hidden attributes within admin API responses

Published: 2022-09-28 Fixed in: 3.6.10

Strapi is vulnerable to Insufficient Session Expiration

Published: 2025-10-16 Fixed in: 5.24.1

Strapi 4.1.12 Cross-site Scripting via crafted file

Published: 2022-07-14 No fix available

Insecure password handling vulnerability in Strapi

Published: 2022-05-04 Fixed in: 3.6.9

Making all attributes on a content-type public without noticing it

Published: 2023-07-25 Fixed in: 4.10.8

Improper Removal of Sensitive Information Before Storage or Transfer in Strapi

Published: 2022-05-20 Fixed in: 3.6.9

Unauthorized Access to Private Fields in User Registration API

Published: 2023-11-03 Fixed in: 4.13.1

Strapi leaking sensitive user information by filtering on private fields

Published: 2023-04-19 Fixed in: 4.8.0

Strapi Server-Side Request Forgery (SSRF)

Published: 2024-06-20 No fix available

Strapi may leak sensitive data via relational filtering due to lack of query sanitization

Published: 2026-05-14 Fixed in: 5.37.0

Alternatives to Strapi

Other CMS projects in the Node.js ecosystem worth evaluating.

Support Options for Strapi

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Strapi — without relying on volunteer maintainers.

Talk to an Expert →