apostrophecms has 3 CVEs on record. 2 were published in the last 90 days. The median CVSS is 8.7 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.7
- Publish → KEV
- —
- Last 90 days
- 2 prev 1
Products
- @apostrophecms/import-export 1
- @apostrophecms/seo 1
- sanitize-html 1
Worst active — by depth score
CVE-2026-44990Critical· 9.3ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API63CVE-2026-53608High· 8.7@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag48CVE-2026-63667Medium· 6.5ApostropheCMS is an open-source Node.js content management system36
apostrophecms vulnerabilities
CVEs affecting apostrophecms, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-63667Medium· 6.5ApostropheCMS is an open-source Node.js content management system
ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip.js constructs an attachment source path from the attacker-controlled _id, name, and ex…
CVE-2026-53608High· 8.7@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
CVE-2026-44990Critical· 9.3PoCApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-contro…