Keystonejs / Keystone
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-63421 | Keystone: `graphql.maxTake` bypass with negative `take` | HIGH | 7.5 | Aug 21, 2026 |
| CVE-2026-10802 | keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption | MEDIUM | 5.3 | Jun 4, 2026 |
| CVE-2026-33326 | @keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany | MEDIUM | 4.3 | Mar 24, 2026 |
| CVE-2025-46720 | Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields | MEDIUM | 4.3 | May 5, 2025 |
| CVE-2023-40027 | Conditionally missing authorization in @keystone-6/core | MEDIUM | 5.3 | Aug 15, 2023 |
| CVE-2023-34247 | @keystone-6/auth Open Redirect vulnerability | MEDIUM | 6.1 | Jun 13, 2023 |
| CVE-2022-39382 | NODE_ENV in Keystone defaults to development with esbuild | CRITICAL | 9.8 | Nov 3, 2022 |
| CVE-2022-39322 | @keystone-6/core vulnerable to field-level access-control bypass for multiselect field | CRITICAL | 9.8 | Oct 25, 2022 |
| CVE-2022-29354 | An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file. | CRITICAL | 9.8 | May 16, 2022 |
| CVE-2022-0087 | Cross-site Scripting (XSS) - Reflected in keystonejs/keystone | MEDIUM | 6.1 | Jan 11, 2022 |
| CVE-2015-9240 | Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct passwor… | HIGH | 7.5 | May 29, 2018 |
| CVE-2017-16570 | KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. In oth… | HIGH | 8.8 | Nov 6, 2017 |
| CVE-2017-15881 | Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the… | MEDIUM | 4.8 | Oct 24, 2017 |
| CVE-2017-15879 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-bet… | HIGH | 8.8 | Oct 24, 2017 |
| CVE-2017-15878 | A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature. | MEDIUM | 6.1 | Oct 24, 2017 |
Showing 1 to 15 of 15 CVEs