Known Vulnerabilities for Directus by Rangerstudio
Listed below are 10 of the newest known vulnerabilities associated with "Directus" by "Rangerstudio".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-61836 json | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is en... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-61835 json | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Dire... | Not Provided | 2026-07-15 | 2026-07-21 |
| CVE-2026-7729 json | A security flaw has been discovered in pixelsock directus-mcp 1.0.0. This issue affects the function validateUrl of the file ... | Not Provided | 2026-05-04 | 2026-05-04 |
| CVE-2023-27474 json | Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed reset U... | 5.4 - MEDIUM | 2023-03-06 | 2023-03-13 |
| CVE-2022-24814 json | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized JavaScr... | 6.1 - MEDIUM | 2022-04-04 | 2022-04-12 |
| CVE-2022-23080 json | In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload fun... | 5 - MEDIUM | 2022-06-22 | 2023-11-07 |
| CVE-2022-22117 json | In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functiona... | 5.4 - MEDIUM | 2022-01-10 | 2022-01-14 |
| CVE-2022-22116 json | In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG f... | 5.4 - MEDIUM | 2022-01-10 | 2022-01-14 |
| CVE-2021-29641 json | Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include t... | 8.8 - HIGH | 2021-04-07 | 2021-04-13 |
| CVE-2021-27583 json | ** UNSUPPORTED WHEN ASSIGNED ** In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the data... | 5.3 - MEDIUM | 2021-02-23 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 | |||
| Application | Rangerstudio | Directus | 9.0.0 |