Keystonejs

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 16
    Known Exploited: 0
    3
    Critical Level Threats
    5
    High Level Threats
    6
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-63421

    Keystone: `graphql.maxTake` bypass with negative `take`

    Last Modified: Aug 26, 2026
    Published: Aug 21, 2026

    CVE-2026-10802

    keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption

    Last Modified: Jun 04, 2026
    Published: Jun 04, 2026

    CVE-2026-33326

    @keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany

    Last Modified: May 04, 2026
    Published: Mar 24, 2026

    CVE-2025-46720

    Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields

    Last Modified: Sep 19, 2025
    Published: May 05, 2025

    CVE-2023-40027

    Conditionally missing authorization in @keystone-6/core

    Last Modified: Nov 21, 2024
    Published: Aug 15, 2023
    Items Per Page
    Keystonejs Vulnerabilities & Security CVEs | CVE-DB