apostrophecms kayıtları
apostrophecms üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-287 Improper Authentication1
- CWE-613 Insufficient Session Expiration1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2021-25979İstismar yok | Apostrophe - Insufficient Session Expirationapostrophecms · apostrophecms · CWE-613 | Kritik9,8 | — | %1,1 | 8 Kas 2021 |
39İzleyin | CVE-2026-32731Kavram kanıtı | ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extractionapostrophecms · import-export · CWE-22 | Kritik9,9 | — | %0,6 | 18 Mar 2026 |
34İzleyin | CVE-2026-35569İstismar yok | ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMSapostrophecms · apostrophecms · CWE-79 | Yüksek8,7 | — | %0,4 | 15 Nis 2026 |
32İzleyin | CVE-2026-32730İstismar yok | ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middlewareapostrophecms · apostrophecms · CWE-287 | Yüksek8,1 | — | %0,5 | 18 Mar 2026 |
30İzleyin | CVE-2022-25887İstismar yok | Regular Expression Denial of Service (ReDoS)apostrophecms · sanitize-html · CWE-1333 | Yüksek7,5 | — | %1,5 | 30 Ağu 2022 |
24İzleyin | CVE-2016-1000237İstismar yok | sanitize-html before 1.4.3 has XSS.apostrophecms · sanitize-html · CWE-79 | Orta6,1 | — | %0,8 | 23 Oca 2020 |
24İzleyin | CVE-2026-40186İstismar yok | ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elementsapostrophecms · apostrophecms · CWE-79 | Orta6,1 | — | %0,3 | 15 Nis 2026 |
24İzleyin | CVE-2014-125128İstismar yok | 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS).apostrophecms · sanitize-html · CWE-79 | Orta6,1 | — | %0,3 | 8 Eyl 2025 |
24İzleyin | CVE-2019-25225İstismar yok | `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS).apostrophecms · sanitize-html · CWE-79 | Orta6,1 | — | %0,3 | 8 Eyl 2025 |
22İzleyin | CVE-2021-26539İstismar yok | Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attackeapostrophecms · sanitize-html | Orta5,3 | — | %2,0 | 8 Şub 2021 |
22İzleyin | CVE-2021-26540İstismar yok | Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when apostrophecms · sanitize-html | Orta5,3 | — | %1,8 | 8 Şub 2021 |
21İzleyin | CVE-2024-21501İstismar yok | Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attriapostrophecms · sanitize-html · CWE-200 | Orta5,3 | — | %1,0 | 24 Şub 2024 |
21İzleyin | CVE-2026-33888İstismar yok | ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST APIapostrophecms · apostrophecms · CWE-200 | Orta5,3 | — | %0,5 | 15 Nis 2026 |
21İzleyin | CVE-2021-25978İstismar yok | Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious Javapostrophecms · apostrophecms · CWE-79 | Orta5,4 | — | %0,5 | 7 Kas 2021 |
21İzleyin | CVE-2026-39857İstismar yok | Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictionsapostrophecms · apostrophecms · CWE-200 | Orta5,3 | — | %0,4 | 15 Nis 2026 |
21İzleyin | CVE-2026-33889İstismar yok | ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Contextapostrophecms · apostrophecms · CWE-79 | Orta5,4 | — | %0,3 | 15 Nis 2026 |
14İzleyin | CVE-2026-33877İstismar yok | ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpointapostrophecms · apostrophecms · CWE-208 | Düşük3,7 | — | %0,3 | 15 Nis 2026 |
- CVE-2021-2597939İzleyin
Apostrophe - Insufficient Session Expiration
KritikCVSS 9,8İstismar yokEPSS %1apostrophecms · apostrophecms8 Kas 2021
- CVE-2026-3273139İzleyin
ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction
KritikCVSS 9,9Kavram kanıtıEPSS %1apostrophecms · import-export18 Mar 2026
- CVE-2026-3556934İzleyin
ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
YüksekCVSS 8,7İstismar yokEPSS %0apostrophecms · apostrophecms15 Nis 2026
- CVE-2026-3273032İzleyin
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
YüksekCVSS 8,1İstismar yokEPSS %0apostrophecms · apostrophecms18 Mar 2026
- CVE-2022-2588730İzleyin
Regular Expression Denial of Service (ReDoS)
YüksekCVSS 7,5İstismar yokEPSS %1apostrophecms · sanitize-html30 Ağu 2022
- CVE-2016-100023724İzleyin
sanitize-html before 1.4.3 has XSS.
OrtaCVSS 6,1İstismar yokEPSS %1apostrophecms · sanitize-html23 Oca 2020
- CVE-2026-4018624İzleyin
ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements
OrtaCVSS 6,1İstismar yokEPSS %0apostrophecms · apostrophecms15 Nis 2026
- CVE-2014-12512824İzleyin
'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS).
OrtaCVSS 6,1İstismar yokEPSS %0apostrophecms · sanitize-html8 Eyl 2025
- CVE-2019-2522524İzleyin
`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS).
OrtaCVSS 6,1İstismar yokEPSS %0apostrophecms · sanitize-html8 Eyl 2025
- CVE-2021-2653922İzleyin
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacke
OrtaCVSS 5,3İstismar yokEPSS %2apostrophecms · sanitize-html8 Şub 2021
- CVE-2021-2654022İzleyin
Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when
OrtaCVSS 5,3İstismar yokEPSS %2apostrophecms · sanitize-html8 Şub 2021
- CVE-2024-2150121İzleyin
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attri
OrtaCVSS 5,3İstismar yokEPSS %1apostrophecms · sanitize-html24 Şub 2024
- CVE-2026-3388821İzleyin
ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API
OrtaCVSS 5,3İstismar yokEPSS %1apostrophecms · apostrophecms15 Nis 2026
- CVE-2021-2597821İzleyin
Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious Jav
OrtaCVSS 5,4İstismar yokEPSS %0apostrophecms · apostrophecms7 Kas 2021
- CVE-2026-3985721İzleyin
Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions
OrtaCVSS 5,3İstismar yokEPSS %0apostrophecms · apostrophecms15 Nis 2026
- CVE-2026-3388921İzleyin
ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context
OrtaCVSS 5,4İstismar yokEPSS %0apostrophecms · apostrophecms15 Nis 2026
- CVE-2026-3387714İzleyin
ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
DüşükCVSS 3,7İstismar yokEPSS %0apostrophecms · apostrophecms15 Nis 2026