Apostrophe

Apostrophecms · 18 CVEs

CVE-2026-84371
MEDIUM

ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass

Sep 1, 2026

CVE-2026-71553
HIGH

ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS

Aug 17, 2026

CVE-2026-63667
MEDIUM

ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal

Aug 17, 2026

CVE-2026-63670
MEDIUM

ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close

Aug 17, 2026

CVE-2026-63669
MEDIUM

ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-…

Aug 17, 2026

CVE-2026-53609
CRITICAL

Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authoriz…

Jun 12, 2026

CVE-2026-53607
LOW

@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header

Jun 12, 2026

CVE-2026-45014
MEDIUM

Apostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Display Name in Draft Version Tooltip

Jun 12, 2026

CVE-2026-45013
HIGH

Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation

Jun 12, 2026

CVE-2026-45012
HIGH

Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget

Jun 12, 2026

CVE-2026-45011
HIGH

Apostrophe has stored XSS via javascript: URL in Image Widget Link

Jun 12, 2026

CVE-2026-40186
MEDIUM

ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements

Apr 15, 2026

CVE-2026-39857
MEDIUM

Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions

Apr 15, 2026

CVE-2026-35569
HIGH

ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS

Apr 15, 2026

CVE-2026-33889
MEDIUM

ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context

Apr 15, 2026

CVE-2026-33888
MEDIUM

ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API

Apr 15, 2026

CVE-2026-33877
LOW

ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint

Apr 15, 2026

CVE-2026-32730
HIGH

ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware

Mar 18, 2026

Showing 1 to 18 of 18 CVEs