CVE Tools

Keystonejs

3 CVEs tracked since 2017. Since Oct 2017, none of them reached CISA KEV.

Keystonejs CVEs per month

Oct 2017 to Oct 2017. Point at a month, or focus the strip and use the arrow keys.
Keystonejs CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-1030

Products

The products that kept showing up in Keystonejs's monthly top three, with their CVEs summed over those months.

  1. Keystone31 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Keystonejs.

  1. CVE-2026-63421Keystone: `graphql.maxTake` bypass with negative `take`7.5
  2. CVE-2026-10802keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption4.3
  3. CVE-2026-33326@keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany4.3
  4. CVE-2025-46720Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields3.1
  5. CVE-2023-40027Conditionally missing authorization in @keystone-6/core3.7
  6. CVE-2023-34247@keystone-6/auth Open Redirect vulnerability6.1
  7. CVE-2022-39382NODE_ENV in Keystone defaults to development with esbuild9.8
  8. CVE-2022-39322@keystone-6/core vulnerable to field-level access-control bypass for multiselect field9.1
  9. CVE-2022-29354An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file.9.8
  10. CVE-2022-0087Cross-site Scripting (XSS) - Reflected in keystonejs/keystone6.1
  11. CVE-2021-32624Private Field data leak7.5
  12. CVE-2015-9240Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct password is still required to complete sign in.7.5
  13. CVE-2017-16570KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. In other words, it fails to reject requests ...8.8
  14. CVE-2017-15881Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the "content brief" or "content extended" ...4.8
  15. CVE-2017-15879CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that is mishandled in ...8.8

The record

Peak rank
#116 in Oct 2017
Busiest month shown
Oct 2017, 3 CVEs
Months with a KEV entry
0 since Oct 2017
Monthly snapshots
1 since 2017
Keystonejs's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store