apostrophecms records
17 published records for vendor apostrophecms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-287 Improper Authentication1
- CWE-613 Insufficient Session Expiration1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-25979No exploit | Apostrophe - Insufficient Session Expirationapostrophecms · apostrophecms · CWE-613 | Critical9.8 | — | 1.1% | Nov 8, 2021 |
39Monitor | CVE-2026-32731Proof of concept | ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extractionapostrophecms · import-export · CWE-22 | Critical9.9 | — | 0.6% | Mar 18, 2026 |
34Monitor | CVE-2026-35569No exploit | ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMSapostrophecms · apostrophecms · CWE-79 | High8.7 | — | 0.4% | Apr 15, 2026 |
32Monitor | CVE-2026-32730No exploit | ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middlewareapostrophecms · apostrophecms · CWE-287 | High8.1 | — | 0.5% | Mar 18, 2026 |
30Monitor | CVE-2022-25887No exploit | Regular Expression Denial of Service (ReDoS)apostrophecms · sanitize-html · CWE-1333 | High7.5 | — | 1.5% | Aug 30, 2022 |
24Monitor | CVE-2016-1000237No exploit | sanitize-html before 1.4.3 has XSS.apostrophecms · sanitize-html · CWE-79 | Medium6.1 | — | 0.8% | Jan 23, 2020 |
24Monitor | CVE-2026-40186No exploit | ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elementsapostrophecms · apostrophecms · CWE-79 | Medium6.1 | — | 0.3% | Apr 15, 2026 |
24Monitor | CVE-2014-125128No exploit | 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS).apostrophecms · sanitize-html · CWE-79 | Medium6.1 | — | 0.3% | Sep 8, 2025 |
24Monitor | CVE-2019-25225No exploit | `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS).apostrophecms · sanitize-html · CWE-79 | Medium6.1 | — | 0.3% | Sep 8, 2025 |
22Monitor | CVE-2021-26539No exploit | Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attackeapostrophecms · sanitize-html | Medium5.3 | — | 2.0% | Feb 8, 2021 |
22Monitor | CVE-2021-26540No exploit | Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when apostrophecms · sanitize-html | Medium5.3 | — | 1.8% | Feb 8, 2021 |
21Monitor | CVE-2024-21501No exploit | Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attriapostrophecms · sanitize-html · CWE-200 | Medium5.3 | — | 1.0% | Feb 24, 2024 |
21Monitor | CVE-2026-33888No exploit | ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST APIapostrophecms · apostrophecms · CWE-200 | Medium5.3 | — | 0.5% | Apr 15, 2026 |
21Monitor | CVE-2021-25978No exploit | Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious Javapostrophecms · apostrophecms · CWE-79 | Medium5.4 | — | 0.5% | Nov 7, 2021 |
21Monitor | CVE-2026-39857No exploit | Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictionsapostrophecms · apostrophecms · CWE-200 | Medium5.3 | — | 0.4% | Apr 15, 2026 |
21Monitor | CVE-2026-33889No exploit | ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Contextapostrophecms · apostrophecms · CWE-79 | Medium5.4 | — | 0.3% | Apr 15, 2026 |
14Monitor | CVE-2026-33877No exploit | ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpointapostrophecms · apostrophecms · CWE-208 | Low3.7 | — | 0.3% | Apr 15, 2026 |
- CVE-2021-2597939Monitor
Apostrophe - Insufficient Session Expiration
CriticalCVSS 9.8No exploitEPSS 1%apostrophecms · apostrophecmsNov 8, 2021
- CVE-2026-3273139Monitor
ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction
CriticalCVSS 9.9Proof of conceptEPSS 1%apostrophecms · import-exportMar 18, 2026
- CVE-2026-3556934Monitor
ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
HighCVSS 8.7No exploitEPSS 0%apostrophecms · apostrophecmsApr 15, 2026
- CVE-2026-3273032Monitor
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
HighCVSS 8.1No exploitEPSS 0%apostrophecms · apostrophecmsMar 18, 2026
- CVE-2022-2588730Monitor
Regular Expression Denial of Service (ReDoS)
HighCVSS 7.5No exploitEPSS 1%apostrophecms · sanitize-htmlAug 30, 2022
- CVE-2016-100023724Monitor
sanitize-html before 1.4.3 has XSS.
MediumCVSS 6.1No exploitEPSS 1%apostrophecms · sanitize-htmlJan 23, 2020
- CVE-2026-4018624Monitor
ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements
MediumCVSS 6.1No exploitEPSS 0%apostrophecms · apostrophecmsApr 15, 2026
- CVE-2014-12512824Monitor
'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS).
MediumCVSS 6.1No exploitEPSS 0%apostrophecms · sanitize-htmlSep 8, 2025
- CVE-2019-2522524Monitor
`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS).
MediumCVSS 6.1No exploitEPSS 0%apostrophecms · sanitize-htmlSep 8, 2025
- CVE-2021-2653922Monitor
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacke
MediumCVSS 5.3No exploitEPSS 2%apostrophecms · sanitize-htmlFeb 8, 2021
- CVE-2021-2654022Monitor
Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when
MediumCVSS 5.3No exploitEPSS 2%apostrophecms · sanitize-htmlFeb 8, 2021
- CVE-2024-2150121Monitor
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attri
MediumCVSS 5.3No exploitEPSS 1%apostrophecms · sanitize-htmlFeb 24, 2024
- CVE-2026-3388821Monitor
ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API
MediumCVSS 5.3No exploitEPSS 1%apostrophecms · apostrophecmsApr 15, 2026
- CVE-2021-2597821Monitor
Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious Jav
MediumCVSS 5.4No exploitEPSS 0%apostrophecms · apostrophecmsNov 7, 2021
- CVE-2026-3985721Monitor
Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions
MediumCVSS 5.3No exploitEPSS 0%apostrophecms · apostrophecmsApr 15, 2026
- CVE-2026-3388921Monitor
ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context
MediumCVSS 5.4No exploitEPSS 0%apostrophecms · apostrophecmsApr 15, 2026
- CVE-2026-3387714Monitor
ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
LowCVSS 3.7No exploitEPSS 0%apostrophecms · apostrophecmsApr 15, 2026