Apostrophe Technologies ApostropheCMS是Apostrophe Technologies公司开源的一个全栈内容管理系统。 Apostrophe Technologies ApostropheCMS 4.32.0之前版本存在授权问题漏洞,该漏洞源于页面模块的move()操作未能强制检查目标父级的_create权限,可能导致已认证的编辑或贡献者通过页面REST更新端点使用_targetId和_position将受控页面移动到受限子树,并重新排序受保护的同级页面。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| apostrophecms | apostrophe | < 4.32.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| apostrophecms | apostrophe | < 4.32.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71553 | 7.1 HIGH | ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persisten |
| CVE-2026-63667 | 6.5 MEDIUM | ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal |
| CVE-2026-63670 | 6.1 MEDIUM | ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close |
No comments yet