apostrophecms是Apostrophecms公司开源的一个内容管理系统。 ApostropheCMS 4.30.0及之前版本存在安全漏洞,该漏洞源于当启用prettyUrls功能时,公开的pretty-URL处理器使用原始的Host HTTP请求标头构建上游URL,可能导致未经身份验证的远程攻击者利用此漏洞发起服务端请求伪造攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| apostrophecms | apostrophe | <= 4.30.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| apostrophecms | apostrophe | <= 4.30.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44990 | 9.3 CRITICAL | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html` |
| CVE-2026-53609 | 9.1 CRITICAL | Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that l |
| CVE-2026-53608 | 8.7 HIGH | @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Inje |
| CVE-2026-45013 | 8.1 HIGH | Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Inpu |
| CVE-2026-45012 | 7.6 HIGH | Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/valid |
| CVE-2026-45011 | 7.3 HIGH | Apostrophe has stored XSS via javascript: URL in Image Widget Link |
| CVE-2026-42853 | 6.5 MEDIUM | @apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input |
| CVE-2026-53606 | 5.4 MEDIUM | sanitize-html has an incomplete URI scheme validation that allows javascript: URIs through |
| CVE-2026-45014 | Apostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Display Name in |
No comments yet