Skip to content
Noroxi

apostrophecms records

17 published records for vendor apostrophecms.

All records

17 records
  • Apostrophe - Insufficient Session Expiration

    CriticalCVSS 9.8No exploitEPSS 1%

    apostrophecms · apostrophecmsNov 8, 2021

  • ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction

    CriticalCVSS 9.9Proof of conceptEPSS 1%

    apostrophecms · import-exportMar 18, 2026

  • ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS

    HighCVSS 8.7No exploitEPSS 0%

    apostrophecms · apostrophecmsApr 15, 2026

  • ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware

    HighCVSS 8.1No exploitEPSS 0%

    apostrophecms · apostrophecmsMar 18, 2026

  • Regular Expression Denial of Service (ReDoS)

    HighCVSS 7.5No exploitEPSS 1%

    apostrophecms · sanitize-htmlAug 30, 2022

  • sanitize-html before 1.4.3 has XSS.

    MediumCVSS 6.1No exploitEPSS 1%

    apostrophecms · sanitize-htmlJan 23, 2020

  • ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements

    MediumCVSS 6.1No exploitEPSS 0%

    apostrophecms · apostrophecmsApr 15, 2026

  • 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS).

    MediumCVSS 6.1No exploitEPSS 0%

    apostrophecms · sanitize-htmlSep 8, 2025

  • `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS).

    MediumCVSS 6.1No exploitEPSS 0%

    apostrophecms · sanitize-htmlSep 8, 2025

  • Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacke

    MediumCVSS 5.3No exploitEPSS 2%

    apostrophecms · sanitize-htmlFeb 8, 2021

  • Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when

    MediumCVSS 5.3No exploitEPSS 2%

    apostrophecms · sanitize-htmlFeb 8, 2021

  • Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attri

    MediumCVSS 5.3No exploitEPSS 1%

    apostrophecms · sanitize-htmlFeb 24, 2024

  • ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API

    MediumCVSS 5.3No exploitEPSS 1%

    apostrophecms · apostrophecmsApr 15, 2026

  • Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious Jav

    MediumCVSS 5.4No exploitEPSS 0%

    apostrophecms · apostrophecmsNov 7, 2021

  • Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions

    MediumCVSS 5.3No exploitEPSS 0%

    apostrophecms · apostrophecmsApr 15, 2026

  • ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context

    MediumCVSS 5.4No exploitEPSS 0%

    apostrophecms · apostrophecmsApr 15, 2026

  • ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint

    LowCVSS 3.7No exploitEPSS 0%

    apostrophecms · apostrophecmsApr 15, 2026