Directus
This hub aggregates every CVE we track for Directus, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
65
CVEs tracked
3
Critical
16
High
0
In CISA KEV
Severity distribution
MEDIUM44HIGH16CRITICAL3LOW2
Monthly trend
4
2
2
1
0
2
1
1
5
0
0
0
4
1
0
0
4
0
1
1
0
10
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Directus.
- CVE-2026-39943Directus exposes sensitive fields in revision history6.5
- CVE-2026-39942Directus has a Path Traversal and Broken Access Control in File Management API8.5
- CVE-2026-35442Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries8.1
- CVE-2026-35441Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity Limits6.5
- CVE-2026-35413Directus GraphQL Schema SDL Disclosure Setting5.3
- CVE-2026-35412Directus has a TUS Upload Authorization Bypass Allows Arbitrary File Overwrite7.1
- CVE-2026-35411Directus is an Open Redirect in Admin 2FA Setup Page4.3
- CVE-2026-35410Directus has an Open Redirect via Parser Bypass in OAuth2/SAML Authentication Flow6.1
- CVE-2026-35409Directus has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File Import7.7
- CVE-2026-35408Directus is Missing Cross-Origin Opener Policy8.7
- CVE-2026-26185Directus Affected by User Enumeration via Password Reset Timing Attack5.3
- CVE-2026-22032Directus has open redirect in SAML4.3
- CVE-2025-64749Directus Vulnerable to Information Leakage in Existing Collections4.3
- CVE-2025-64748Directus's conceal fields are searchable if read permissions enabled6.5
- CVE-2025-64747Directus Vulnerable to Stored Cross-site Scripting5.5
Product normalization is registry-driven with AI assist and human review. How it works