Product
monospace directus
65 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-39943
CVE-2026-39942
CVE-2026-35442
CVE-2026-35441
CVE-2026-35413
CVE-2026-35412
CVE-2026-35411
CVE-2026-35410
CVE-2026-35409
CVE-2026-35408
CVE-2026-26185
CVE-2026-22032
CVE-2025-64749
CVE-2025-64748
CVE-2025-64747
CVE-2025-64746
CVE-2025-55746
CVE-2025-53889
CVE-2025-53887
CVE-2025-53886
CVE-2025-53885
CVE-2025-30353
CVE-2025-30352
CVE-2025-30351
CVE-2025-30350
CVE-2025-30225
CVE-2025-27089
CVE-2025-24353
CVE-2024-54151
CVE-2024-54128
CVE-2024-47822
CVE-2024-46990
CVE-2024-45596
CVE-2024-6534
CVE-2024-6533
CVE-2024-39896
CVE-2024-39895
CVE-2024-39701
CVE-2024-39699
CVE-2024-36128
CVE-2024-34709
CVE-2024-34708
CVE-2024-28239
CVE-2024-28238
CVE-2024-27296
CVE-2024-27295
CVE-2023-45820
CVE-2023-38503
CVE-2020-19850
CVE-2023-28443
CVE-2023-27481
CVE-2023-27474
CVE-2023-26492
CVE-2022-26969
CVE-2022-36031
CVE-2022-23080
CVE-2022-24814
CVE-2022-22117
CVE-2022-22116
CVE-2021-29641
CVE-2021-27583
CVE-2021-26595
CVE-2021-26594
CVE-2021-26593
CVE-2018-10723
< 11.17.0
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revision record
< 11.17.0
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint
< 11.17.0
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max)
< 11.17.0
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/g
< 11.16.1
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPECTION=fals
< 11.16.1
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload
< 11.16.1
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerable to an op
< 11.16.1
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability
< 11.16.0
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request Forgery (
< 11.17.0
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO)
< 11.15.0
Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enumeration v
< 11.14.0
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redirect vulner
< 11.13.0
Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was f
< 11.13.0
Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11.13.0 allo
< 11.13.0
Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vulnerability
< 11.13.0
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not prope
>= 10.8.0 and < 11.9.3
Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exi
>= 9.12.0 and < 11.9.0
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 1
>= 9.0.0 and < 11.9.0
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11
>= 9.0.0 and < 11.9.0
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11
>= 9.0.0 and < 11.9.0
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11
>= 9.12.0 and < 11.5.0
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 1
>= 9.0.1 and < 11.5.0
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and prior to ve
>= 10.10.0 and < 11.5.0
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.10.0 and prior to version
>= 9.22.0 and < 11.5.0
Directus is a real-time API and App dashboard for managing SQL database content. The
@directus/storage-driver-s3 package startin>= 9.22.0 and < 11.5.0
Directus is a real-time API and App dashboard for managing SQL database content. The
@directus/storage-driver-s3 package startin>= 11.0.0 and < 11.1.2
Directus is a real-time API and App dashboard for managing SQL database content. In affected versions if there are two overlapping
< 11.2.0
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.2.0, when sharing an item, a
>= 11.0.0 and < 11.3.0
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to version 1
>= 10.10.0 and < 10.13.4
Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to p
< 10.13.2
Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are not redacted
< 10.13.3
Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost usin
< 10.13.3
Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of
all versions
Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another u
all versions
Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client. This is possible becaus
< 10.13.0
Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combination with
< 10.12.0
Directus is a real-time API and App dashboard for managing SQL database content. A denial of service (DoS) attack by field duplica
>= 9.23.0 and < 10.6.0
Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly handles _
< 10.9.3
Directus is a real-time API and App dashboard for managing SQL database content. There was already a reported SSRF vulnerability v
< 10.11.2
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.2, providing a non-numeric length
< 10.11.0
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens function like th
< 10.11.0
Directus is a real-time API and App dashboard for managing SQL database content. A user with permission to view any collection usi
< 10.10.0
Directus is a real-time API and App dashboard for managing SQL database content. The authentication API has a
redirect parameter< 10.10.0
Directus is a real-time API and App dashboard for managing SQL database content. When reaching the /files page, a JWT is passed vi
< 10.8.3
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Directus versi
< 10.8.3
Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Directus back
>= 10.4.0 and < 10.6.2
Directus is a real-time API and App dashboard for managing SQL database content. In affected versions any Directus installation th
>= 10.3.0 and < 10.5.0
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to version 1
all versions
An issue found in Directus API v.2.2.0 allows a remote attacker to cause a denial of service via a great amount of HTTP requests.
< 9.23.3
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_to
< 9.16.0
Directus is a real-time API and App dashboard for managing SQL database content. In versions prior to 9.16.0 users with read acces
< 9.23.0
Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed reset URL ar
< 9.23.0
Directus is a real-time API and App dashboard for managing SQL database content. Directus is vulnerable to Server-Side Request For
< 9.7.0
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
< 9.15.0
Directus is a free and open-source data platform for headless content management. The Directus process can be aborted by having an
>= 9.0.1 and <= 9.6.0
In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload function
< 9.7.0
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized JavaScript (
>= 9.0.1 and <= 9.4.1
In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality,
>= 9.0.1 and <= 9.4.1
In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file u
>= 8.0.0 and < 8.8.2
Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include the ab
>= 8.0.0 and <= 8.8.1
In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset featu
>= 8.0.0 and <= 8.8.1
In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by
>= 8.0.0 and <= 8.8.1
In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the
>= 8.0.0 and <= 8.8.1
In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they get in resp
all versions
Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.