← Global Threat Landscape

CVE-2023-22894

CWE-312

High

Raised to High: in CISA KEV (known exploited)

63.6

RPS

Description

Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from API responses. If the attacker has super admin access, then this can be exploited to discover the password hash and password reset token of all users. If the attacker has admin panel access to an account with permission to access the username and email of API users with a lower privileged role (e.g., Editor or Author), then this can be exploited to discover sensitive information for all API users but not other admin accounts.

Source: NVD

Signals

CVSS
4.9
Medium · v3.1
EPSS
1.65%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Oct 2026
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-312
Published
19 Apr 2023
Last modified 8 Oct 2026

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2023-22894

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 9 Oct 2026, 05:16 UK time

CVE-2023-22894 · RPS 63.6 · DevSecure Intelligence