MEDIUMnpm
GHSA-2cjv-6wg9-f4f3· CVE-2025-25298Strapi Password Hashing is Missing Maximum Password Length Validation
Modified: 11/27/2025
package
pkg:npm/%40strapi/core
Strapi Password Hashing is Missing Maximum Password Length Validation
Modified: 11/27/2025
Strapi Allows Unauthorized Access to Private Fields via parms.lookup
Modified: 10/16/2025
Strapi core vulnerable to sensitive data exposure via CORS misconfiguration
Modified: 2/3/2026