Keystonejs
Keystonejs Keystone: vulnerabilidades y CVE
Keystonejs Keystone tiene 14 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses2
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-10802 | Baja (2.1) | 0.31% | — | 4 jun 2026 | A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL API Endpoint. The… |
| CVE-2026-33326 | Media (4.3) | 0.28% | — | 24 mar 2026 | Keystone is a content management system for Node.js. Prior to version 6.5.2, {field}.isFilterable access control can be bypassed in findMany queries by passing a cursor. This can be used to confirm the existence of… |
| CVE-2025-46720 | Media (4.3) | 0.27% | — | 5 may 2025 | Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can be bypassed in `update` and `delete` mutations by adding additional unique filters. These filters… |
| CVE-2023-40027 | Media (5.3) | 0.58% | — | 15 ago 2023 | Keystone is an open source headless CMS for Node.js — built with GraphQL and React. When `ui.isAccessAllowed` is set as `undefined`, the `adminMeta` GraphQL query is publicly accessible (no session required). This is… |
| CVE-2023-34247 | Media (4.1) | 0.41% | — | 13 jun 2023 | Keystone is a content management system for Node.JS. There is an open redirect in the `@keystone-6/auth` package versions 7.0.0 and prior, where the redirect leading `/` filter can be bypassed. Users may be redirected… |
| CVE-2022-39382 | Crítica (9.8) | 1.6% | — | 3 nov 2022 | Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/core@3.0.0 || 3.0.1` users that use `NODE_ENV` to trigger security-sensitive functionality in their production builds are vulnerable to… |
| CVE-2022-39322 | Crítica (9.8) | 1.2% | — | 25 oct 2022 | @keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multiselect` fields to use the field-level… |
| CVE-2022-29354 | Crítica (9.8) | 2.4% | — | 16 may 2022 | An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file. |
| CVE-2022-0087 | Media (6.1) | 2.6% | — | 12 ene 2022 | keystone is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2015-9240 | Alta (7.5) | 0.89% | — | 29 may 2018 | Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct password is still required to complete sign in. |
| CVE-2017-16570 | Alta (8.8) | 2.2% | — | 6 nov 2017 | KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. In other words, it fails to reject requests that lack an… |
| CVE-2017-15881 | Media (4.8) | 1.2% | — | 24 oct 2017 | Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the "content brief" or "content extended" field, a different… |
| CVE-2017-15879 | Alta (8.8) | 7.2% | — | 24 oct 2017 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that is mishandled in a CSV export. |
| CVE-2017-15878 | Media (6.1) | 3.4% | — | 24 oct 2017 | A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature. |