VDB
Sign up

package

npm/apostrophe

pkg:npm/apostrophe

CRITICAL9.1npm
GHSA-6h5j-32cf-4253· CVE-2026-53609

Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass

Modified: 7/31/2026

MEDIUM5.4npm
GHSA-97v6-998m-fp4g· CVE-2026-33889

ApostropheCMS: Stored XSS via CSS Custom Property Injection in @apostrophecms/color-field Escaping Style Tag Context

Modified: 4/16/2026

MEDIUM5.3npm
GHSA-c276-fj82-f2pq· CVE-2026-39857

ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions

Modified: 4/16/2026

MEDIUM6.5npm
GHSA-wr5r-wqp2-x4fh· CVE-2026-63669

ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree

Modified: 9/3/2026