apostrophe vulnerabilities
CVEs whose affected-version data names the apostrophe package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-71553HighApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
▾ Twilightapostrophe · apostropheEPSS 0.31%via GHSA
CVE-2026-63669Medium· 6.5ApostropheCMS is an open-source Node.js content management system
ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission because its oldParent archive condition disables the chec…
▾ Sunlitapostrophe · apostropheEPSS 0.22%via NVD
CVE-2026-53609Critical· 9.1Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
▾ Midnightapostrophe · apostropheEPSS 0.24%via GHSA
CVE-2026-53607Low· 3.7@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
▾ Sunlitapostrophe · apostropheEPSS 0.23%via GHSA