@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Modified: 7/31/2026
package
pkg:npm/apostrophe
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Modified: 7/31/2026
Cross-site Scripting in apostrophe
Modified: 11/8/2023
Apostrophe has stored XSS via javascript: URL in Image Widget Link
Modified: 6/12/2026
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
Modified: 7/31/2026
Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
Modified: 5/5/2026
ApostropheCMS: Stored XSS via CSS Custom Property Injection in @apostrophecms/color-field Escaping Style Tag Context
Modified: 4/16/2026
Apostrophe CMS Insufficient Session Expiration vulnerability
Modified: 11/8/2023
ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions
Modified: 4/16/2026
Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation
Modified: 6/12/2026
Open Redirect in apostrophe
Modified: 9/28/2021
ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
Modified: 4/16/2026
Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget
Modified: 6/12/2026
Denial of Service in apostrophe
Modified: 8/31/2020
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
Modified: 3/19/2026
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
Modified: 9/2/2026
ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
Modified: 9/3/2026
ApostropheCMS: publicApiProjection Bypass via project Query Builder in Piece-Type REST API
Modified: 4/16/2026