apostrophecms是Apostrophecms公司开源的一个内容管理系统。 ApostropheCMS 2.17.5之前版本存在跨站脚本漏洞,该漏洞源于allowedSchemesAppliedToAttributes(默认:['href', 'src', 'cite'])未能包含HTML规范定义的action、formaction等10+个接受URI的属性,当开发者配置允许这些属性时,javascript等危险URI方案完全通过,导致跨站脚本攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| apostrophecms | sanitize-html | < 2.17.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| apostrophecms | sanitize-html | < 2.17.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44990 | 9.3 CRITICAL | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html` |
| CVE-2026-53609 | 9.1 CRITICAL | Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that l |
| CVE-2026-53608 | 8.7 HIGH | @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Inje |
| CVE-2026-45013 | 8.1 HIGH | Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Inpu |
| CVE-2026-45012 | 7.6 HIGH | Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/valid |
| CVE-2026-45011 | 7.3 HIGH | Apostrophe has stored XSS via javascript: URL in Image Widget Link |
| CVE-2026-42853 | 6.5 MEDIUM | @apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input |
| CVE-2026-53607 | 3.7 LOW | @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header |
| CVE-2026-45014 | Apostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Display Name in |
No comments yet