VendorsMonospacedirectusany version
Vulnerabilities

Monospace Directus any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

53CVEs
CVE-2022-26969
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
Published 2022-12-26 · Modified
9.8EPSS 0.009
CVE-2025-55746
Directus allows unauthenticated file upload and file modification due to lacking input sanitization
Published 2025-08-20 · Analyzed
9.3EPSS 0.013
CVE-2026-35408
Directus is Missing Cross-Origin Opener Policy
Published 2026-04-06 · Analyzed
9.3EPSS 0.002
CVE-2026-39942
Directus has a Path Traversal and Broken Access Control in File Management API
Published 2026-04-09 · Analyzed
8.8EPSS 0.004
CVE-2025-30353
Directus's webhook trigger flows can leak sensitive data
Published 2025-03-26 · Analyzed
8.6EPSS 0.005
CVE-2026-61836
Directus: Authorization-dependent response served from unsegmented cache key
Published 2026-07-15 · Analyzed
8.6EPSS 0.005
CVE-2024-27295
Directus MySQL accent insensitive email matching
Published 2024-03-01 · Analyzed
8.2EPSS 0.007
CVE-2026-35442
Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries
Published 2026-04-06 · Analyzed
8.1EPSS 0.004
CVE-2026-35412
Directus has a TUS Upload Authorization Bypass Allows Arbitrary File Overwrite
Published 2026-04-06 · Analyzed
8.1EPSS 0.004
CVE-2024-39701
Directus Incorrectly handles _in` filter
Published 2024-07-08 · Analyzed
7.7EPSS 0.004
CVE-2026-61835
Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
Published 2026-07-15 · Analyzed
7.7EPSS 0.004
CVE-2026-35409
Directus has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File Import
Published 2026-04-06 · Analyzed
7.7EPSS 0.004
CVE-2023-26492
Directus vulnerable to Server-Side Request Forgery On File Import
Published 2023-03-03 · Modified
7.5EPSS 0.010
CVE-2024-36128
Directus is soft-locked by providing a string value to random string util
Published 2024-06-03 · Analyzed
7.5EPSS 0.006
CVE-2024-54151
Directus allows unauthenticated access to WebSocket events and operations
Published 2024-12-09 · Analyzed
7.5EPSS 0.006
CVE-2024-39896
Directus allows SSO User Enumeration
Published 2024-07-08 · Analyzed
7.5EPSS 0.005
CVE-2024-45596
Directus's session is cached for OpenID and OAuth2 if `redirect` is not used
Published 2024-09-10 · Analyzed
7.4EPSS 0.007
CVE-2022-36031
Unhandled exception on illegal filename_disk value
Published 2022-08-19 · Modified
6.5EPSS 0.010
CVE-2024-39895
Directus GraphQL Field Duplication Denial of Service (DoS)
Published 2024-07-08 · Analyzed
6.5EPSS 0.008
CVE-2023-45820
Directus crashes on invalid WebSocket message
Published 2023-10-19 · Modified
6.5EPSS 0.007
CVE-2023-38503
Directus has Incorrect Permission Checking for GraphQL Subscriptions
Published 2023-07-25 · Modified
6.5EPSS 0.005
CVE-2026-35441
Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity Limits
Published 2026-04-06 · Analyzed
6.5EPSS 0.004
CVE-2025-53889
Directus missing permission checks for manual trigger Flows
Published 2025-07-14 · Analyzed
6.5EPSS 0.004
CVE-2025-64748
Directus's conceal fields are searchable if read permissions enabled
Published 2025-11-13 · Analyzed
6.5EPSS 0.003
CVE-2026-39943
Directus exposes sensitive fields in revision history
Published 2026-04-09 · Analyzed
6.5EPSS 0.003
CVE-2026-35410
Directus has an Open Redirect via Parser Bypass in OAuth2/SAML Authentication Flow
Published 2026-04-06 · Analyzed
6.1EPSS 0.003
CVE-2026-22032
Directus has open redirect in SAML
Published 2026-01-08 · Analyzed
6.1EPSS 0.002
CVE-2024-54128
Directus has an HTML Injection in Comment
Published 2024-12-05 · Analyzed
5.7EPSS 0.003
CVE-2023-28443
directus vulnerable to Insertion of Sensitive Information into Log File
Published 2023-03-23 · Modified
5.5EPSS 0.003
CVE-2025-64747
Directus Vulnerable to Stored Cross-site Scripting
Published 2025-11-13 · Analyzed
5.5EPSS 0.002
CVE-2024-28239
URL Redirection to Untrusted Site in OAuth2/OpenID in directus
Published 2024-03-12 · Analyzed
5.4EPSS 0.006
CVE-2024-34709
Directus Lacks Session Tokens Invalidation
Published 2024-05-13 · Analyzed
5.4EPSS 0.005
CVE-2025-27089
Overlapping policies allow update to non-allowed fields in directus
Published 2025-02-19 · Analyzed
5.4EPSS 0.002
CVE-2025-64746
Directus has Improper Permission Handling on Deleted Fields
Published 2025-11-13 · Analyzed
5.4EPSS 0.002
CVE-2025-53887
Directus's exact version number is exposed by the OpenAPI Spec
Published 2025-07-14 · Analyzed
5.3EPSS 0.009
CVE-2024-27296
Directus version number disclosure
Published 2024-03-01 · Analyzed
5.3EPSS 0.006
CVE-2026-26185
Directus Affected by User Enumeration via Password Reset Timing Attack
Published 2026-02-12 · Analyzed
5.3EPSS 0.004
CVE-2025-30225
Directus's S3 assets become unavailable after a burst of malformed transformations
Published 2025-03-26 · Analyzed
5.3EPSS 0.004
CVE-2025-30350
Directus's S3 assets become unavailable after a burst of HEAD requests
Published 2025-03-26 · Analyzed
5.3EPSS 0.004
CVE-2025-30352
Directus `search` query parameter allows enumeration of non permitted fields
Published 2025-03-26 · Analyzed
5.3EPSS 0.004
1 / 2Next →