CVE Tools

Apostrophecms

20 CVEs tracked since 2021. Since Feb 2021, none of them reached CISA KEV.

Apostrophecms CVEs per month

Feb 2021 to Jun 2026. Point at a month, or focus the strip and use the arrow keys.
Apostrophecms CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-0220
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-1120
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-0460
2026-05null or fewer
2026-06100

Products

The products that kept showing up in Apostrophecms's monthly top three, with their CVEs summed over those months.

  1. Apostrophe122 months
  2. Apostrophecms82 months
  3. Sanitize-html53 months
  4. @apostrophecms/cli11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Apostrophecms.

  1. CVE-2026-84371ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass5.4
  2. CVE-2026-71553ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS—
  3. CVE-2026-63667ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal6.5
  4. CVE-2026-63670ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close6.1
  5. CVE-2026-63669ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree6.5
  6. CVE-2026-53609Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass9.1
  7. CVE-2026-53608@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag8.7
  8. CVE-2026-53607@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header3.7
  9. CVE-2026-53606sanitize-html has an incomplete URI scheme validation that allows javascript: URIs through action, formaction, data, poster, and background attributes5.4
  10. CVE-2026-45014Apostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Display Name in Draft Version Tooltip—
  11. CVE-2026-45013Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation8.1
  12. CVE-2026-45012Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget7.6
  13. CVE-2026-45011Apostrophe has stored XSS via javascript: URL in Image Widget Link7.3
  14. CVE-2026-44990Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`9.3
  15. CVE-2026-42853@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input6.5

The record

Peak rank
#125 in Jun 2026
Busiest month shown
Jun 2026, 10 CVEs
Months with a KEV entry
0 since Feb 2021
Monthly snapshots
4 since 2021
Apostrophecms's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store