CVE Tools

Directus

27 CVEs tracked since 2024. Since Mar 2024, none of them reached CISA KEV.

Directus CVEs per month

Mar 2024 to Apr 2026. Point at a month, or focus the strip and use the arrow keys.
Directus CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-0340
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-0740
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-0350
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-1140
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04100

Products

The products that kept showing up in Directus's monthly top three, with their CVEs summed over those months.

  1. Directus275 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Directus.

  1. CVE-2026-10716Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation—
  2. CVE-2026-61836Directus: Authorization-dependent response served from unsegmented cache key8.6
  3. CVE-2026-61835Directus: SSRF Protection Bypass via 0.0.0.0 in File Import7.7
  4. CVE-2026-39943Directus exposes sensitive fields in revision history6.5
  5. CVE-2026-39942Directus has a Path Traversal and Broken Access Control in File Management API8.5
  6. CVE-2026-35442Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries8.1
  7. CVE-2026-35441Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity Limits6.5
  8. CVE-2026-35413Directus GraphQL Schema SDL Disclosure Setting5.3
  9. CVE-2026-35412Directus has a TUS Upload Authorization Bypass Allows Arbitrary File Overwrite7.1
  10. CVE-2026-35411Directus is an Open Redirect in Admin 2FA Setup Page4.3
  11. CVE-2026-35410Directus has an Open Redirect via Parser Bypass in OAuth2/SAML Authentication Flow6.1
  12. CVE-2026-35409Directus has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File Import7.7
  13. CVE-2026-35408Directus is Missing Cross-Origin Opener Policy8.7
  14. CVE-2026-26185Directus Affected by User Enumeration via Password Reset Timing Attack5.3
  15. CVE-2026-22032Directus has open redirect in SAML4.3

The record

Peak rank
#105 in Apr 2026
Busiest month shown
Apr 2026, 10 CVEs
Months with a KEV entry
0 since Mar 2024
Monthly snapshots
5 since 2024
Directus's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store