Keystonejs

Keystone

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.31%
  • Veröffentlicht 04.06.2026 11:15:10
  • Zuletzt bearbeitet 04.06.2026 16:10:59

A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL API Endpoint. The manipulation results in resource ...

  • EPSS 0.26%
  • Veröffentlicht 24.03.2026 19:08:05
  • Zuletzt bearbeitet 04.05.2026 15:26:15

Keystone is a content management system for Node.js. Prior to version 6.5.2, {field}.isFilterable access control can be bypassed in findMany queries by passing a cursor. This can be used to confirm the existence of records by protected field values. ...

  • EPSS 0.23%
  • Veröffentlicht 05.05.2025 18:53:51
  • Zuletzt bearbeitet 19.09.2025 19:53:56

Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can be bypassed in `update` and `delete` mutations by adding additional unique filters. These filters can be used as an oracle to probe...

  • EPSS 0.47%
  • Veröffentlicht 15.08.2023 18:15:10
  • Zuletzt bearbeitet 21.11.2024 08:18:33

Keystone is an open source headless CMS for Node.js — built with GraphQL and React. When `ui.isAccessAllowed` is set as `undefined`, the `adminMeta` GraphQL query is publicly accessible (no session required). This is different to the behaviour of the...

  • EPSS 0.41%
  • Veröffentlicht 13.06.2023 17:15:14
  • Zuletzt bearbeitet 21.11.2024 08:06:51

Keystone is a content management system for Node.JS. There is an open redirect in the `@keystone-6/auth` package versions 7.0.0 and prior, where the redirect leading `/` filter can be bypassed. Users may be redirected to domains other than the relati...

Exploit
  • EPSS 1.49%
  • Veröffentlicht 03.11.2022 14:15:23
  • Zuletzt bearbeitet 21.11.2024 07:18:10

Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/core@3.0.0 || 3.0.1` users that use `NODE_ENV` to trigger security-sensitive functionality in their production builds are vulnerable to `NODE_ENV` being inlined to `"d...

Exploit
  • EPSS 1.06%
  • Veröffentlicht 25.10.2022 17:15:56
  • Zuletzt bearbeitet 21.11.2024 07:18:02

@keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multiselect` fields to use the field-level access control - if configured - ...

Exploit
  • EPSS 2.41%
  • Veröffentlicht 16.05.2022 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:58:57

An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file.

Exploit
  • EPSS 2.6%
  • Veröffentlicht 12.01.2022 00:15:10
  • Zuletzt bearbeitet 21.11.2024 06:37:53

keystone is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • EPSS 0.89%
  • Veröffentlicht 29.05.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 02:40:07

Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct password is still required to complete sign in.