VendorsKeystoneJSkeystoneany version
Vulnerabilities

KeystoneJS Keystone any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2022-39322
@keystone-6/core vulnerable to field-level access-control bypass for multiselect field
Published 2022-10-25 · Modified
9.8EPSS 0.012
CVE-2017-15879
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that is mishandled in a CSV export.
Published 2017-10-24 · Modified
8.81 PoCEPSS 0.072
CVE-2017-16570
KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. In other words, it fails to reject requests that lack an x-csrf-token header.
Published 2017-11-06 · Modified
8.81 PoCEPSS 0.022
CVE-2015-9240
Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct password is still required to complete sign in.
Published 2018-05-29 · Modified
7.5EPSS 0.009
CVE-2022-0087
Cross-site Scripting (XSS) - Reflected in keystonejs/keystone
Published 2022-01-11 · Modified
7.1EPSS 0.026
CVE-2017-15878
A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature.
Published 2017-10-24 · Modified
6.11 PoCEPSS 0.034
CVE-2023-34247
@keystone-6/auth Open Redirect vulnerability
Published 2023-06-13 · Modified
6.1EPSS 0.004
CVE-2023-40027
Conditionally missing authorization in @keystone-6/core
Published 2023-08-15 · Modified
5.3EPSS 0.006
CVE-2017-15881
Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the "content brief" or "content extended" field, a different vulnerability than CVE-2017-15878.
Published 2017-10-24 · Modified
4.8EPSS 0.012
CVE-2026-33326
@keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany
Published 2026-03-24 · Analyzed
4.3EPSS 0.003
CVE-2025-46720
Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields
Published 2025-05-05 · Analyzed
4.3EPSS 0.003