İçeriğe atla
Noroxi

apostrophecms kayıtları

apostrophecms üreticisine ait 17 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%100
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

17 kayıt
  • CVE-2021-25979
    39İzleyin

    Apostrophe - Insufficient Session Expiration

    KritikCVSS 9,8İstismar yokEPSS %1

    apostrophecms · apostrophecms8 Kas 2021

  • CVE-2026-32731
    39İzleyin

    ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction

    KritikCVSS 9,9Kavram kanıtıEPSS %1

    apostrophecms · import-export18 Mar 2026

  • CVE-2026-35569
    34İzleyin

    ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS

    YüksekCVSS 8,7İstismar yokEPSS %0

    apostrophecms · apostrophecms15 Nis 2026

  • CVE-2026-32730
    32İzleyin

    ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware

    YüksekCVSS 8,1İstismar yokEPSS %0

    apostrophecms · apostrophecms18 Mar 2026

  • CVE-2022-25887
    30İzleyin

    Regular Expression Denial of Service (ReDoS)

    YüksekCVSS 7,5İstismar yokEPSS %1

    apostrophecms · sanitize-html30 Ağu 2022

  • sanitize-html before 1.4.3 has XSS.

    OrtaCVSS 6,1İstismar yokEPSS %1

    apostrophecms · sanitize-html23 Oca 2020

  • CVE-2026-40186
    24İzleyin

    ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements

    OrtaCVSS 6,1İstismar yokEPSS %0

    apostrophecms · apostrophecms15 Nis 2026

  • CVE-2014-125128
    24İzleyin

    'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS).

    OrtaCVSS 6,1İstismar yokEPSS %0

    apostrophecms · sanitize-html8 Eyl 2025

  • CVE-2019-25225
    24İzleyin

    `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS).

    OrtaCVSS 6,1İstismar yokEPSS %0

    apostrophecms · sanitize-html8 Eyl 2025

  • CVE-2021-26539
    22İzleyin

    Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacke

    OrtaCVSS 5,3İstismar yokEPSS %2

    apostrophecms · sanitize-html8 Şub 2021

  • CVE-2021-26540
    22İzleyin

    Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when

    OrtaCVSS 5,3İstismar yokEPSS %2

    apostrophecms · sanitize-html8 Şub 2021

  • CVE-2024-21501
    21İzleyin

    Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attri

    OrtaCVSS 5,3İstismar yokEPSS %1

    apostrophecms · sanitize-html24 Şub 2024

  • CVE-2026-33888
    21İzleyin

    ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API

    OrtaCVSS 5,3İstismar yokEPSS %1

    apostrophecms · apostrophecms15 Nis 2026

  • CVE-2021-25978
    21İzleyin

    Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious Jav

    OrtaCVSS 5,4İstismar yokEPSS %0

    apostrophecms · apostrophecms7 Kas 2021

  • CVE-2026-39857
    21İzleyin

    Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions

    OrtaCVSS 5,3İstismar yokEPSS %0

    apostrophecms · apostrophecms15 Nis 2026

  • CVE-2026-33889
    21İzleyin

    ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context

    OrtaCVSS 5,4İstismar yokEPSS %0

    apostrophecms · apostrophecms15 Nis 2026

  • CVE-2026-33877
    14İzleyin

    ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint

    DüşükCVSS 3,7İstismar yokEPSS %0

    apostrophecms · apostrophecms15 Nis 2026