CVE-2023-22894: Strapi Strapi
- Vendor
- Strapi
- Product
- Strapi
- Vulnerability
- Strapi Cleartext Storage of Sensitive Information Vulnerability
- Date added
- Oct 8, 2026
- CISA due date (U.S. federal agencies)
- Oct 11, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-312
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.08
About this page
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.