« Back to list

Monospace

Monospace Directus: vulnerabilities and CVEs

Monospace Directus has 56 published vulnerabilities, 18 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs56
Last 12 months18
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-61836High (8.6)0.47%—Jul 15, 2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is enabled, the cache-key derivation in api/src/utils/get-cache-key.ts includes version, path,…
CVE-2026-61835High (7.7)0.41%—Jul 15, 2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Directus's file-import-from-URL feature can be bypassed using the address 0.0.0.0 because…
CVE-2026-39943Medium (6.5)0.27%—Apr 9, 2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revision records (in directus_revisions) whenever items are created or updated. Due to the revision…
CVE-2026-39942High (8.8)0.36%—Apr 9, 2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter. By setting this value to match the…
CVE-2026-35442High (8.1)0.43%—Apr 6, 2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields with the conceal special type incorrectly return raw database values…
CVE-2026-35441Medium (6.5)0.42%—Apr 6, 2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql/system) did not deduplicate resolver invocations within a single…
CVE-2026-35413Medium (5.3)0.36%—Apr 6, 2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPECTION=false is configured, Directus correctly blocks standard GraphQL introspection queries…
CVE-2026-35412High (8.1)0.39%—Apr 6, 2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tus) allows any authenticated user with basic file upload permissions to…
CVE-2026-35411Medium (4.3)0.33%—Apr 6, 2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerable to an open redirect via the redirect query parameter on the /admin/tfa-setup page. When an…
CVE-2026-35410Medium (6.1)0.32%—Apr 6, 2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login redirection logic. The isLoginRedirectAllowed function fails to…
CVE-2026-35409High (7.7)0.38%—Apr 6, 2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request Forgery (SSRF) protection bypass has been identified and fixed in Directus. The IP address…
CVE-2026-35408Critical (9.3)0.19%—Apr 6, 2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy (COOP) HTTP response header. Without…
CVE-2026-26185Medium (5.3)0.43%—Feb 12, 2026
Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enumeration vulnerability exists in the password reset functionality. When an invalid reset_url…
CVE-2026-22032Medium (6.1)0.23%—Jan 8, 2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redirect vulnerability exists in the Directus SAML authentication callback endpoint. During SAML…
CVE-2025-64749Medium (4.3)0.33%—Nov 13, 2025
Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was found in the Directus REST API in versions of Directus prior to version 11.13.0. The…
CVE-2025-64748Medium (6.5)0.28%—Nov 13, 2025
Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11.13.0 allows authenticated users to search concealed/sensitive fields when they have read…
CVE-2025-64747Medium (5.5)0.25%—Nov 13, 2025
Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 11.13.0 that allows users with `upload files` and `edit…
CVE-2025-64746Medium (5.4)0.19%—Nov 13, 2025
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not properly clean up field-level permissions when a field is deleted. When a field is removed…
CVE-2025-55746High (7.5)1.3%—Aug 20, 2025
Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing…
CVE-2025-53889Medium (6.5)0.41%—Jul 15, 2025
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.9.0, Directus Flows with a manual trigger are not validating whether the user…
CVE-2025-53887Medium (5.3)0.92%—Jul 15, 2025
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Directus version number is incorrectly being used as OpenAPI Spec version…
CVE-2025-53886Medium (4.5)0.40%—Jul 15, 2025
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows with the WebHook trigger all incoming request details are…
CVE-2025-53885Medium (4.2)0.18%—Jul 15, 2025
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows to handle CRUD events for users it is possible to log the…
CVE-2025-30353High (7.5)0.52%—Mar 26, 2025
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.5.0, when a Flow with the "Webhook" trigger and the "Data of Last Operation" response…
CVE-2025-30352Medium (5.3)0.37%—Mar 26, 2025
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and prior to version 11.5.0, the `search` query parameter allows users with access to a collection to…
CVE-2025-30351Medium (4.3)0.37%—Mar 26, 2025
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.10.0 and prior to version 11.5.0, a suspended user can use the token generated in session auth mode to access the…
CVE-2025-30350Medium (5.3)0.43%—Mar 26, 2025
Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in…
CVE-2025-30225Medium (5.3)0.43%—Mar 26, 2025
Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in…
CVE-2025-27089Medium (4.3)0.24%—Feb 19, 2025
Directus is a real-time API and App dashboard for managing SQL database content. In affected versions if there are two overlapping policies for the `update` action that allow access to different fields, instead of…
CVE-2025-24353Medium (4.3)0.39%—Jan 23, 2025
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.2.0, when sharing an item, a typical user can specify an arbitrary role. It allows the user to use a higher-privileged…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services5
  2. T1005 Data from Local System2
  3. T1090 Proxy2
  4. T1565.002 Transmitted Data Manipulation2
  5. T1078 Valid Accounts1
  6. T1189 Drive-by Compromise1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.