apostrophecms是Apostrophecms公司开源的一个内容管理系统。 ApostropheCMS 4.29.0及之前版本存在跨站脚本漏洞,该漏洞源于未经清理的用户显示名称,可能导致在草稿版本工具提示中存储跨站脚本攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| apostrophecms | apostrophe | <= 4.29.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| apostrophecms | apostrophe | <= 4.29.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44990 | 9.3 CRITICAL | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html` |
| CVE-2026-53609 | 9.1 CRITICAL | Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that l |
| CVE-2026-53608 | 8.7 HIGH | @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Inje |
| CVE-2026-45013 | 8.1 HIGH | Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Inpu |
| CVE-2026-45012 | 7.6 HIGH | Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/valid |
| CVE-2026-45011 | 7.3 HIGH | Apostrophe has stored XSS via javascript: URL in Image Widget Link |
| CVE-2026-42853 | 6.5 MEDIUM | @apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input |
| CVE-2026-53606 | 5.4 MEDIUM | sanitize-html has an incomplete URI scheme validation that allows javascript: URIs through |
| CVE-2026-53607 | 3.7 LOW | @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header |
No comments yet