Monospace
Monospace Directus: vulnerabilities and CVEs
Monospace Directus has 56 published vulnerabilities, 18 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs56
Last 12 months18
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61836 | High (8.6) | 0.47% | — | Jul 15, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is enabled, the cache-key derivation in api/src/utils/get-cache-key.ts includes version, path,… |
| CVE-2026-61835 | High (7.7) | 0.41% | — | Jul 15, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Directus's file-import-from-URL feature can be bypassed using the address 0.0.0.0 because… |
| CVE-2026-39943 | Medium (6.5) | 0.27% | — | Apr 9, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revision records (in directus_revisions) whenever items are created or updated. Due to the revision… |
| CVE-2026-39942 | High (8.8) | 0.36% | — | Apr 9, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter. By setting this value to match the… |
| CVE-2026-35442 | High (8.1) | 0.43% | — | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields with the conceal special type incorrectly return raw database values… |
| CVE-2026-35441 | Medium (6.5) | 0.42% | — | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql/system) did not deduplicate resolver invocations within a single… |
| CVE-2026-35413 | Medium (5.3) | 0.36% | — | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPECTION=false is configured, Directus correctly blocks standard GraphQL introspection queries… |
| CVE-2026-35412 | High (8.1) | 0.39% | — | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tus) allows any authenticated user with basic file upload permissions to… |
| CVE-2026-35411 | Medium (4.3) | 0.33% | — | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerable to an open redirect via the redirect query parameter on the /admin/tfa-setup page. When an… |
| CVE-2026-35410 | Medium (6.1) | 0.32% | — | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login redirection logic. The isLoginRedirectAllowed function fails to… |
| CVE-2026-35409 | High (7.7) | 0.38% | — | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request Forgery (SSRF) protection bypass has been identified and fixed in Directus. The IP address… |
| CVE-2026-35408 | Critical (9.3) | 0.19% | — | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy (COOP) HTTP response header. Without… |
| CVE-2026-26185 | Medium (5.3) | 0.43% | — | Feb 12, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enumeration vulnerability exists in the password reset functionality. When an invalid reset_url… |
| CVE-2026-22032 | Medium (6.1) | 0.23% | — | Jan 8, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redirect vulnerability exists in the Directus SAML authentication callback endpoint. During SAML… |
| CVE-2025-64749 | Medium (4.3) | 0.33% | — | Nov 13, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was found in the Directus REST API in versions of Directus prior to version 11.13.0. The… |
| CVE-2025-64748 | Medium (6.5) | 0.28% | — | Nov 13, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11.13.0 allows authenticated users to search concealed/sensitive fields when they have read… |
| CVE-2025-64747 | Medium (5.5) | 0.25% | — | Nov 13, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 11.13.0 that allows users with `upload files` and `edit… |
| CVE-2025-64746 | Medium (5.4) | 0.19% | — | Nov 13, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not properly clean up field-level permissions when a field is deleted. When a field is removed… |
| CVE-2025-55746 | High (7.5) | 1.3% | — | Aug 20, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing… |
| CVE-2025-53889 | Medium (6.5) | 0.41% | — | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.9.0, Directus Flows with a manual trigger are not validating whether the user… |
| CVE-2025-53887 | Medium (5.3) | 0.92% | — | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Directus version number is incorrectly being used as OpenAPI Spec version… |
| CVE-2025-53886 | Medium (4.5) | 0.40% | — | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows with the WebHook trigger all incoming request details are… |
| CVE-2025-53885 | Medium (4.2) | 0.18% | — | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows to handle CRUD events for users it is possible to log the… |
| CVE-2025-30353 | High (7.5) | 0.52% | — | Mar 26, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.5.0, when a Flow with the "Webhook" trigger and the "Data of Last Operation" response… |
| CVE-2025-30352 | Medium (5.3) | 0.37% | — | Mar 26, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and prior to version 11.5.0, the `search` query parameter allows users with access to a collection to… |
| CVE-2025-30351 | Medium (4.3) | 0.37% | — | Mar 26, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.10.0 and prior to version 11.5.0, a suspended user can use the token generated in session auth mode to access the… |
| CVE-2025-30350 | Medium (5.3) | 0.43% | — | Mar 26, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in… |
| CVE-2025-30225 | Medium (5.3) | 0.43% | — | Mar 26, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in… |
| CVE-2025-27089 | Medium (4.3) | 0.24% | — | Feb 19, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. In affected versions if there are two overlapping policies for the `update` action that allow access to different fields, instead of… |
| CVE-2025-24353 | Medium (4.3) | 0.39% | — | Jan 23, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.2.0, when sharing an item, a typical user can specify an arbitrary role. It allows the user to use a higher-privileged… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.