CVE-2026-39943
- EPSS 0.04%
- Veröffentlicht 09.04.2026 17:16:29
- Zuletzt bearbeitet 14.04.2026 17:34:15
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revision records (in directus_revisions) whenever items are created or updated. Due to the revision snapshot code not consistently call...
CVE-2026-39942
- EPSS 0.03%
- Veröffentlicht 09.04.2026 17:16:29
- Zuletzt bearbeitet 14.04.2026 17:36:25
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter. By setting this value to match the storage path of another user's fil...
CVE-2026-35442
- EPSS 0.04%
- Veröffentlicht 06.04.2026 21:36:57
- Zuletzt bearbeitet 20.04.2026 16:32:37
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields with the conceal special type incorrectly return raw database values instead of the masked placeholder...
CVE-2026-35441
- EPSS 0.04%
- Veröffentlicht 06.04.2026 21:36:07
- Zuletzt bearbeitet 20.04.2026 16:34:49
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql/system) did not deduplicate resolver invocations within a single request. An authenticated user coul...
CVE-2026-35413
- EPSS 0.05%
- Veröffentlicht 06.04.2026 21:34:32
- Zuletzt bearbeitet 20.04.2026 16:36:51
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPECTION=false is configured, Directus correctly blocks standard GraphQL introspection queries (__schema, __type). However, the serve...
CVE-2026-35412
- EPSS 0.03%
- Veröffentlicht 06.04.2026 21:33:44
- Zuletzt bearbeitet 20.04.2026 16:40:33
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tus) allows any authenticated user with basic file upload permissions to overwrite arbitrary existing f...
CVE-2026-35411
- EPSS 0.05%
- Veröffentlicht 06.04.2026 21:33:06
- Zuletzt bearbeitet 20.04.2026 16:43:32
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerable to an open redirect via the redirect query parameter on the /admin/tfa-setup page. When an administrator who has not yet configu...
CVE-2026-35410
- EPSS 0.04%
- Veröffentlicht 06.04.2026 21:32:13
- Zuletzt bearbeitet 20.04.2026 16:43:55
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login redirection logic. The isLoginRedirectAllowed function fails to correctly identify certain malformed...
CVE-2026-35409
- EPSS 0.03%
- Veröffentlicht 06.04.2026 21:31:13
- Zuletzt bearbeitet 20.04.2026 16:47:30
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request Forgery (SSRF) protection bypass has been identified and fixed in Directus. The IP address validation mechanism used to block req...
CVE-2026-35408
- EPSS 0.02%
- Veröffentlicht 06.04.2026 21:30:22
- Zuletzt bearbeitet 20.04.2026 16:53:51
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy (COOP) HTTP response header. Without this header, a malicious cross-ori...