VendorsMonospacedirectusany version
Vulnerabilities

Monospace Directus any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

53CVEs
CVE-2026-35413
Directus GraphQL Schema SDL Disclosure Setting
Published 2026-04-06 · Analyzed
5.3EPSS 0.004
CVE-2024-46990
SSRF Loopback IP filter bypass in directus
Published 2024-09-18 · Analyzed
5.0EPSS 0.005
CVE-2024-39699
Directus has a Blind SSRF On File Import
Published 2024-07-08 · Modified
5.0EPSS 0.004
CVE-2025-24353
Directus privilege escalation vulnerability using Share feature
Published 2025-01-23 · Analyzed
5.0EPSS 0.004
CVE-2024-34708
Directus allows redacted data extraction on the API through "alias"
Published 2024-05-13 · Analyzed
4.9EPSS 0.008
CVE-2025-53886
Directus doesn't redact tokens in Flow logs
Published 2025-07-14 · Analyzed
4.5EPSS 0.004
CVE-2023-27481
Extract password hashes through export querying in directus
Published 2023-03-07 · Modified
4.3EPSS 0.006
CVE-2025-30351
Suspended Directus user can continue to use session token to access API
Published 2025-03-26 · Analyzed
4.3EPSS 0.004
CVE-2025-64749
Directus Vulnerable to Information Leakage in Existing Collections
Published 2025-11-13 · Analyzed
4.3EPSS 0.003
CVE-2026-35411
Directus is an Open Redirect in Admin 2FA Setup Page
Published 2026-04-06 · Analyzed
4.3EPSS 0.003
CVE-2024-47822
Directus inserts access token from query string into logs
Published 2024-10-08 · Modified
4.2EPSS 0.003
CVE-2025-53885
Directus doesn't redact sensitive user data when logging via event hooks
Published 2025-07-14 · Analyzed
4.2EPSS 0.002
CVE-2024-28238
Session Token in URL in directus
Published 2024-03-12 · Analyzed
2.3EPSS 0.002
← Prev2 / 2