Monospace

Directus

44 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 12.02.2026 21:54:13
  • Zuletzt bearbeitet 20.02.2026 21:09:03

Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enumeration vulnerability exists in the password reset functionality. When an invalid reset_url parameter is provided, the response t...

  • EPSS 0.09%
  • Veröffentlicht 08.01.2026 14:32:06
  • Zuletzt bearbeitet 20.01.2026 18:15:40

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redirect vulnerability exists in the Directus SAML authentication callback endpoint. During SAML authentication, the `RelayState` param...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 13.11.2025 21:34:54
  • Zuletzt bearbeitet 08.12.2025 15:02:34

Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was found in the Directus REST API in versions of Directus prior to version 11.13.0. The `/items/{collection}` API returns di...

  • EPSS 0.04%
  • Veröffentlicht 13.11.2025 21:29:44
  • Zuletzt bearbeitet 08.12.2025 15:00:53

Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11.13.0 allows authenticated users to search concealed/sensitive fields when they have read permissions. While actual values remain ...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 13.11.2025 21:13:42
  • Zuletzt bearbeitet 19.11.2025 14:49:11

Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 11.13.0 that allows users with `upload files` and `edit item` permissions to inject malicio...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 13.11.2025 20:54:42
  • Zuletzt bearbeitet 08.12.2025 14:58:27

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not properly clean up field-level permissions when a field is deleted. When a field is removed from a collection, its reference i...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 20.08.2025 17:58:06
  • Zuletzt bearbeitet 13.01.2026 18:29:53

Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents ...

  • EPSS 0.07%
  • Veröffentlicht 14.07.2025 23:50:23
  • Zuletzt bearbeitet 16.07.2025 14:20:25

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.9.0, Directus Flows with a manual trigger are not validating whether the user triggering the Flow has permissions to t...

  • EPSS 0.07%
  • Veröffentlicht 14.07.2025 23:40:59
  • Zuletzt bearbeitet 16.07.2025 14:19:39

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Directus version number is incorrectly being used as OpenAPI Spec version this means that it is being ex...

  • EPSS 0.05%
  • Veröffentlicht 14.07.2025 23:35:56
  • Zuletzt bearbeitet 16.07.2025 14:19:03

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows with the WebHook trigger all incoming request details are logged including security sens...