Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

apostrophe — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in apostrophe, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the product apostrophe, a content management system by Apostrophe, categorized by weakness type and vendor tag. It collects records of security flaws affecting this specific software, covering advisories from its initial release through the most recent updates. Readers can use this section to track the vendor's advisory history, analyze the specific weakness classes involved, and review the complete vulnerability timeline for the product. The data provides a factual overview of security issues, allowing teams to identify recurring patterns and assess the overall security posture of the platform. This aggregation serves as a centralized reference for security professionals monitoring the evolution of risks associated with the apostrophe application.

Vendor: apostrophecms

CVE ID Title CVSS Severity Published
CVE-2026-84371 ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass CWE-79 5.4 Medium 2026-09-01
CVE-2026-71553 ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS CWE-1321 7.1 High 2026-08-17
CVE-2026-63667 ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal CWE-22 6.5 Medium 2026-08-17
CVE-2026-63670 ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close CWE-79 6.1 Medium 2026-08-17
CVE-2026-63669 ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree CWE-639 6.5 Medium 2026-08-17
CVE-2026-53609 Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass CWE-1321 9.1 Critical 2026-06-12
CVE-2026-53607 @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header CWE-918 3.7 Low 2026-06-12
CVE-2026-45014 Apostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Display Name in Draft Version Tooltip CWE-79 - - 2026-06-12
CVE-2026-45013 Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation CWE-20 8.1 High 2026-06-12
CVE-2026-45012 Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget CWE-918 7.6 High 2026-06-12
CVE-2026-45011 Apostrophe has stored XSS via javascript: URL in Image Widget Link CWE-79 7.3 High 2026-06-12
CVE-2026-40186 ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements CWE-79 6.1 Medium 2026-04-15
CVE-2026-39857 Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions CWE-200 5.3 Medium 2026-04-15
CVE-2026-35569 ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS CWE-79 8.7 High 2026-04-15
CVE-2026-33889 ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context CWE-79 5.4 Medium 2026-04-15
CVE-2026-33888 ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API CWE-863 5.3 Medium 2026-04-15
CVE-2026-33877 ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint CWE-208 3.7 Low 2026-04-15
CVE-2026-32730 ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware CWE-287 8.1 High 2026-03-18

All 18 known CVE vulnerabilities affecting apostrophe with full Chinese analysis, references, and POCs where available.