shouldiuse.io

Categories

VERDICT

Should I use Directus?

The collaborative backend and self-hostable headless CMS over any database. No-code interface, REST + GraphQL APIs, and MCP for Claude, ChatGPT, and Cursor. - directus.io

Depends. Buy it if you have a developer and want an open-source backend/CMS layered over your own SQL database. Skip it if you want turnkey hosting, predictable pricing, or cannot commit to patching a product with recurring CVEs.

Confidence

Medium. Based on 14 public sources; review volume and pricing data were largely absent, so confidence is medium.

Ratings

  • Value for money
  • Ease of useNo usability data in reviewed sources
  • Feature depth
  • Support qualityNo support evidence found
  • Security posture

Pricing

Free

Self-hosted (open source)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • SQL-backed headless CMS projects
  • API-first app backends
  • Self-hosters wanting database control
  • Teams replacing custom admin panels

Not for

  • Teams without a developer to run and patch it
  • Simple blogs or marketing sites — a simpler CMS wins
  • Buyers wanting managed support and predictable SaaS pricing
  • Non-technical editors who only need a content tool

Gotchas - check before you buy

high

CVE-2025-55746 auth bypass — self-hosters must patch promptly

medium

Stored XSS reported repeatedly (2022 and 2025)

medium

Cloud pricing absent from all reviewed sources — confirm costs before budgeting

medium

Self-hosted migrations and maintenance fall entirely on your team

Pros and cons

Pros

  • Open source and self-hostable over any existing SQL database
  • Instant REST + GraphQL APIs, auth, and admin UI included
  • Users report managing complex relational data without vendor lock-in
  • Ranked 6th of 80 headless CMS in G2's Spring 2023 index
  • Maintains a public vulnerability tracker and CVE disclosure process

Cons

  • Multiple CVEs since 2021, including a 2025 auth bypass
  • Stored XSS vulnerabilities surfaced again in late 2025
  • Self-hosting puts patching and ops burden on your team
  • No pricing details found in reviewed sources

Sources & method

Analyzed 9/21/2026 - 10 sources - Several CVEs from 2021–2026, including a 2025 auth bypass; Directus publishes a vulnerability tracker.

official x2review x3security x3news x2
  • CVE-2025-55746 — authentication bypass, Attackers can bypass authentication controls and manipulate the file system without changes reflected in the Directus UI.
  • CVE-2025-27089, Vulnerability in affected versions of the real-time API and App dashboard for managing SQL database content.
  • CVE-2022-24814 — stored XSS, Stored cross-site scripting that could lead to admin account compromise.
  • CVE-2021-29641 — arbitrary file upload, Arbitrary file upload potentially leading to PHP execution in Apache + local-storage setups (Directus < 8.8.2).

Key stats

  • Value for money: 4/5

    Rating

  • Free

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money: 4/5. Free self-hosting; cloud pricing unverified
  • Ease of use. No usability data in reviewed sources
  • Feature depth: 5/5. REST+GraphQL, auth, no-code admin over any SQL DB
  • Support quality. No support evidence found
  • Security posture: 2/5. Recurring CVEs; 2025 auth bypass disclosed
  • 6th of 80 G2 Headless CMS ranking Spring 2023 Results Index
  • Yes Self-hosted free tier Open source, runs over your SQL database
  • 5 Public CVEs in sources 2021–2026, including a 2025 auth bypass

Pricing

Self-hosted (open source)

Free

  • Runs over your existing SQL database
  • No-code admin, REST + GraphQL APIs

Security

Several CVEs from 2021–2026, including a 2025 auth bypass; Directus publishes a vulnerability tracker.

  • CVE-2025-55746 — authentication bypassAttackers can bypass authentication controls and manipulate the file system without changes reflected in the Directus UI.⁶
  • CVE-2025-27089Vulnerability in affected versions of the real-time API and App dashboard for managing SQL database content.⁵
  • CVE-2022-24814 — stored XSSStored cross-site scripting that could lead to admin account compromise.⁷
  • CVE-2021-29641 — arbitrary file uploadArbitrary file upload potentially leading to PHP execution in Apache + local-storage setups (Directus < 8.8.2).

What users say

Review evidence is thin, but the available G2 feedback praises flexible relational data modeling without proprietary lock-in.

“Directus solves the problem of managing complex relational data without locking you into a proprietary system.”
G2 review

Companies that use it

  • ImpactMarket⁹
  • Ripley Entertainment10
Full analysis

Based on 14 public sources; review volume and pricing data were largely absent, so confidence is medium.

Powerful open-source backend/CMS over any SQL DB — great with a dev team, risky if you won't self-patch known CVEs.

Methodology

Based on 14 public sources; review volume and pricing data were largely absent, so confidence is medium.

Sources

  1. review
  2. official
  3. news
  4. review
  5. security
  6. security
  7. security
  8. review
  9. official
  10. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.