CVE Tools

Apostrophe

22 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Apostrophe, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Apostrophe CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Apostrophe CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-031
2026-046
2026-050
2026-066
2026-070
2026-084
2026-091

Severity

How the 22 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical211%
  • High528%
  • Medium950%
  • Low211%

Latest CVEs

The 15 most recently published vulnerabilities affecting Apostrophe.

  1. CVE-2026-84371ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass5.4
  2. CVE-2026-71553ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS—
  3. CVE-2026-63667ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal6.5
  4. CVE-2026-63670ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close6.1
  5. CVE-2026-63669ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree6.5
  6. CVE-2026-53609Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass9.1
  7. CVE-2026-53607@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header3.7
  8. CVE-2026-45014Apostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Display Name in Draft Version Tooltip—
  9. CVE-2026-45013Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation8.1
  10. CVE-2026-45012Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget7.6
  11. CVE-2026-45011Apostrophe has stored XSS via javascript: URL in Image Widget Link7.3
  12. CVE-2026-40186ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements6.1
  13. CVE-2026-39857Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions5.3
  14. CVE-2026-35569ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS8.7
  15. CVE-2026-33889ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context5.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store