apostrophe has 4 CVEs on record. 4 were published in the last 90 days. The median CVSS is 6.5 (medium), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Weakness classes
Products
- apostrophe 4
Worst active — by depth score
CVE-2026-53609Critical· 9.1Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass50CVE-2026-71553HighApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS41CVE-2026-63669Medium· 6.5ApostropheCMS is an open-source Node.js content management system36CVE-2026-53607Low· 3.7@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header20
apostrophe vulnerabilities
CVEs affecting apostrophe, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-71553HighApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
CVE-2026-63669Medium· 6.5ApostropheCMS is an open-source Node.js content management system
ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission because its oldParent archive condition disables the chec…
CVE-2026-53609Critical· 9.1Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
CVE-2026-53607Low· 3.7@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header