apostrophe
npm7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting apostrophepage 1 of 1
- CVE-2021-25978MEDIUMCVSS 5.4EG 5.4✓ Fixed in 3.4.02021-11-07
Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious JavaScript onto the Images module, which triggers XSS once viewed.
- CVE-2021-25979CRITICALCVSS 9.8EG 9.8✓ Fixed in 3.4.02021-11-08
Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device compromised by a third party could not be locked out by those …
- CVE-2026-33877LOWCVSS 3.7EG 3.7✓ Fixed in 4.29.02026-04-15
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-channel vulnerability in the password reset endpoint (/api/v1/@apostrophecms/login/reset-request) that allows unauthenticate…
- CVE-2026-33888MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.29.02026-04-15
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the getRestQuery method of the @apostrophecms/piece-type module, where the method checks whether …
- CVE-2026-33889MEDIUMCVSS 5.4EG 5.4✓ Fixed in 4.29.02026-04-15
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in the @apostrophecms/color-field module, where color values prefixed with -- bypass TinyColor…
- CVE-2026-35569HIGHCVSS 8.7EG 8.7✓ Fixed in 4.29.02026-04-15
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in SEO-related fields (SEO Title and Meta Description), where user-controlled input is rendere…
- CVE-2026-39857MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.29.02026-04-15
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the choices and counts query parameters of the REST API, where these query builders execute Mongo…
Check whether apostrophe is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for apostrophe CVEs against the assets you own.
Start Free Scan →