Directus
73 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Directus, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Directus CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 2 |
| 2025-01 | 2 |
| 2025-02 | 1 |
| 2025-03 | 5 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 4 |
| 2025-08 | 1 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 4 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 13 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 2 |
| 2026-08 | 1 |
| 2026-09 | 0 |
Severity
How the 73 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High18
- Medium44
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Directus.
- CVE-2026-10716Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation—
- CVE-2026-61836Directus: Authorization-dependent response served from unsegmented cache key8.6
- CVE-2026-61835Directus: SSRF Protection Bypass via 0.0.0.0 in File Import7.7
- CVE-2026-39943Directus exposes sensitive fields in revision history6.5
- CVE-2026-39942Directus has a Path Traversal and Broken Access Control in File Management API8.5
- CVE-2026-35442Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries8.1
- CVE-2026-35441Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity Limits6.5
- CVE-2026-35413Directus GraphQL Schema SDL Disclosure Setting5.3
- CVE-2026-35412Directus has a TUS Upload Authorization Bypass Allows Arbitrary File Overwrite7.1
- CVE-2026-35411Directus is an Open Redirect in Admin 2FA Setup Page4.3
- CVE-2026-35410Directus has an Open Redirect via Parser Bypass in OAuth2/SAML Authentication Flow6.1
- CVE-2026-35409Directus has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File Import7.7
- CVE-2026-35408Directus is Missing Cross-Origin Opener Policy8.7
- GHSA-6q22-g298-grjhDirectus: Unauthenticated Denial of Service via GraphQL Alias Amplification of Expensive Health Check Resolver—
- GHSA-mvv8-v4jj-g47jDirectus: Sensitive fields exposed in revision history—
Product grouping is registry-driven, with AI assist and human review. How it works