pkg:npm/directus
共 53 筆 CVECRITICAL2HIGH14MEDIUM35LOW2
✅ 檢查你的版本
所有已知漏洞
- from 0, < 9.7.0
- CRITICAL9.3CVE-2025-55746Directus allows unauthenticated file upload and file modification due to lacking input sanitization>= 10.8.0, < 11.9.3
- HIGH8.8CVE-2022-24814Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in directusfrom 0, < 9.7.0
- from 0, < 11.17.0
- >= 9.12.0, < 11.5.0
- from 0, < 11.17.0
- from 0, < 10.8.3
- HIGH8.1CVE-2026-35442Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queriesfrom 0, < 11.17.0
- from 0, < 11.16.0
- >= 11.0.0, < 11.3.0
- >= 9.11, < 10.13.0
- from 0, < 10.11.2
- >= 10.4.0, < 10.6.2
- HIGH7.5CVE-2023-27474directus vulnerable to HTML Injection in Password Reset email to custom Reset URLfrom 0, < 9.23.0
- from 0, < 10.13.3
- from 0, < 11.16.1
- MEDIUM6.5CVE-2026-35441Directus: GraphQL Alias Amplification Denial of Service Due to Missing Query Cost/Complexity Limitsfrom 0, < 11.17.0
- from 0, < 11.17.0
- from 0, < 11.13.0
- MEDIUM6.5CVE-2025-53889Directus' insufficient permission checks can enable unauthenticated users to manually trigger Flowsfrom 0, < 11.9.0
- >= 2.2.0, < 2.2.1
- from 0, < 9.16.0
- from 0, < 9.15.0
- >= 9.23.0, < 10.6.0
- from 0, < 11.16.1
- >= 10.10.0, < 10.13.4
- >= 10.3.0, < 10.5.0
- from 0, < 11.13.0
- >= 11.0.0, < 11.1.2
- >= 10.10.0, < 10.11.0
- from 0, < 10.10.0
- from 0, < 11.16.1
- from 0, < 11.14.1
- from 0, < 11.9.0
- >= 9.0.0-alpha.4, < 11.5.0
- >= 9.22, < 11.5.0
- MEDIUM5.3CVE-2025-30225Directus's S3 assets become unavailable after a burst of malformed transformations>= 9.22.0, < 11.5.0
- from 0, < 10.8.3
- from 0, < 11.2.0
- from 0, < 10.13.3
- from 0, < 9.23.0
- >= 9.0.0-beta.2, < 9.7.0
- from 0, < 10.11.0
- from 0, < 11.13.0
- MEDIUM4.5CVE-2025-53886Directus tokens are not redacted in flow logs, exposing session credentials to all adminfrom 0, < 11.9.0
- from 0, < 11.16.1
- from 0, < 11.14.0
- from 0, < 11.13.0
- MEDIUM4.2CVE-2025-53885Directus is vulnerable to sensitive data exposure as user data is not being redacted when logged>= 9.0.0, < 11.9.0
- from 0, < 9.23.3
- from 0, < 10.13.2
- >= 10.10.0, < 11.5.0
- from 0, < 10.10.0