Apostrophecms

First CVE: Jan 23, 2020Active for: 7 yearsTotal CVEs: 17
19.7
VTI Score
Low

ApostropheCMS is a modestly represented content-management and publishing platform whose vulnerability footprint concentrates in a focused product line, with the primary exposures centered on the core CMS application and its sanitization and import-export modules. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through input-handling weaknesses such as cross-site scripting and improper neutralization during content generation, as well as authentication and information-disclosure flaws characteristic of web application frameworks. Defenders using this platform should prioritize input-sanitization and authentication-layer patches; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Apostrophecms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2020
6 years ago
Most Recent CVE
Apr 15, 2026
102 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` constructs file-write
Mar 18, 20269.932NONO
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in SEO-related fields (SEO Title an
Apr 15, 20268.730NONO
Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device com
Nov 8, 20219.830NONO
ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/index.js` (lines 386-38
Mar 18, 20268.127NONO
The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment re
Aug 30, 20227.525NONO
ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the ApostropheCMS-maintained sanitize-h
Apr 15, 20266.122NONO
`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom
Sep 8, 20256.122NONO
'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in an
Sep 8, 20256.121NONO
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the choices and counts query parameter
Apr 15, 20265.320NONO
Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious JavaScript onto the Images module, which tr
Nov 7, 20215.420NONO

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
Severity distribution among all CVEs352,713 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (88.2%)
High2 (11.8%)
Unknown0 (0.0%)
User Interaction
None10 (58.8%)
Unknown0 (0.0%)
Required7 (41.2%)
Privileges Required
Low4 (23.5%)
High0 (0.0%)
None13 (76.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Apostrophecms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Apostrophecms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Apostrophecms's Products

Top CWEs