Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

apostrophecms — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting apostrophecms. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ApostropheCMS is a headless CMS focused on content management for modern web applications. Historically, it has faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, with 8 CVEs documented. The platform's modular architecture introduces potential attack surfaces through its rich text editor and custom field types. Notable security characteristics include its PHP-based backend and JavaScript frontend, which may expose it to web application threats. While no major public security incidents have been widely reported, the consistent discovery of vulnerabilities highlights the importance of regular updates and input validation in preventing exploitation.

Found 18 results / 23 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-84371 ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass — apostrophe CWE-79 5.4 Medium 2026-09-01
CVE-2026-71553 ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS — apostrophe CWE-1321 7.1 High 2026-08-17
CVE-2026-63667 ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal — apostrophe CWE-22 6.5 Medium 2026-08-17
CVE-2026-63670 ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close — apostrophe CWE-79 6.1 Medium 2026-08-17
CVE-2026-63669 ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree — apostrophe CWE-639 6.5 Medium 2026-08-17
CVE-2026-53609 Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass — apostrophe CWE-1321 9.1 Critical 2026-06-12
CVE-2026-53607 @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header — apostrophe CWE-918 3.7 Low 2026-06-12
CVE-2026-45014 Apostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Display Name in Draft Version Tooltip — apostrophe CWE-79 - - 2026-06-12
CVE-2026-45013 Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation — apostrophe CWE-20 8.1 High 2026-06-12
CVE-2026-45012 Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget — apostrophe CWE-918 7.6 High 2026-06-12
CVE-2026-45011 Apostrophe has stored XSS via javascript: URL in Image Widget Link — apostrophe CWE-79 7.3 High 2026-06-12
CVE-2026-40186 ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements — apostrophe CWE-79 6.1 Medium 2026-04-15
CVE-2026-39857 Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions — apostrophe CWE-200 5.3 Medium 2026-04-15
CVE-2026-35569 ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS — apostrophe CWE-79 8.7 High 2026-04-15
CVE-2026-33889 ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context — apostrophe CWE-79 5.4 Medium 2026-04-15
CVE-2026-33888 ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API — apostrophe CWE-863 5.3 Medium 2026-04-15
CVE-2026-33877 ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint — apostrophe CWE-208 3.7 Low 2026-04-15
CVE-2026-32730 ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware — apostrophe CWE-287 8.1 High 2026-03-18

This page lists every published CVE security advisory associated with apostrophecms. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.