Apostrophe
Apostrophecms · 18 CVEs
ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
Sep 1, 2026
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
Aug 17, 2026
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
Aug 17, 2026
ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close
Aug 17, 2026
ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-…
Aug 17, 2026
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authoriz…
Jun 12, 2026
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Jun 12, 2026
Apostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Display Name in Draft Version Tooltip
Jun 12, 2026
Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation
Jun 12, 2026
Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget
Jun 12, 2026
Apostrophe has stored XSS via javascript: URL in Image Widget Link
Jun 12, 2026
ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements
Apr 15, 2026
Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions
Apr 15, 2026
ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
Apr 15, 2026
ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context
Apr 15, 2026
ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API
Apr 15, 2026
ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
Apr 15, 2026
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
Mar 18, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-84371 | ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass | MEDIUM | 0.30% | Sep 1, 2026 |
| CVE-2026-71553 | ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS | HIGH | 0.43% | Aug 17, 2026 |
| CVE-2026-63667 | ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal | MEDIUM | 0.46% | Aug 17, 2026 |
| CVE-2026-63670 | ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close | MEDIUM | 0.33% | Aug 17, 2026 |
| CVE-2026-63669 | ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree | MEDIUM | 0.31% | Aug 17, 2026 |
| CVE-2026-53609 | Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass | CRITICAL | 0.38% | Jun 12, 2026 |
| CVE-2026-53607 | @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header | LOW | 0.32% | Jun 12, 2026 |
| CVE-2026-45014 | Apostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Display Name in Draft Version Tooltip | MEDIUM | 0.44% | Jun 12, 2026 |
| CVE-2026-45013 | Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation | HIGH | 0.38% | Jun 12, 2026 |
| CVE-2026-45012 | Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget | HIGH | 0.31% | Jun 12, 2026 |
| CVE-2026-45011 | Apostrophe has stored XSS via javascript: URL in Image Widget Link | HIGH | 0.37% | Jun 12, 2026 |
| CVE-2026-40186 | ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements | MEDIUM | 0.28% | Apr 15, 2026 |
| CVE-2026-39857 | Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions | MEDIUM | 0.38% | Apr 15, 2026 |
| CVE-2026-35569 | ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS | HIGH | 0.44% | Apr 15, 2026 |
| CVE-2026-33889 | ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context | MEDIUM | 0.26% | Apr 15, 2026 |
| CVE-2026-33888 | ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API | MEDIUM | 0.52% | Apr 15, 2026 |
| CVE-2026-33877 | ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint | LOW | 0.32% | Apr 15, 2026 |
| CVE-2026-32730 | ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware | HIGH | 0.48% | Mar 18, 2026 |
Showing 1 to 18 of 18 CVEs