Apostrophecms
ApostropheCMS is a modestly represented content-management and publishing platform whose vulnerability footprint concentrates in a focused product line, with the primary exposures centered on the core CMS application and its sanitization and import-export modules. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through input-handling weaknesses such as cross-site scripting and improper neutralization during content generation, as well as authentication and information-disclosure flaws characteristic of web application frameworks. Defenders using this platform should prioritize input-sanitization and authentication-layer patches; live severity and exploitation counts are shown alongside this summary.
Trends Over Time
The number and severity of CVEs published that impact products developed by Apostrophecms over time
Products(3 total)
Top CVEs
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32731CRITICAL ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`,
The `extract()` function in `gzip.js` constructs file-write | Mar 18, 2026 | 9.9 | 32 | NO | NO |
CVE-2026-35569HIGH ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in SEO-related fields (SEO Title an | Apr 15, 2026 | 8.7 | 30 | NO | NO |
CVE-2021-25979CRITICAL Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device com | Nov 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2026-32730HIGH ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/index.js` (lines 386-38 | Mar 18, 2026 | 8.1 | 27 | NO | NO |
CVE-2022-25887HIGH The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment re | Aug 30, 2022 | 7.5 | 25 | NO | NO |
CVE-2026-40186MEDIUM ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the ApostropheCMS-maintained sanitize-h | Apr 15, 2026 | 6.1 | 22 | NO | NO |
CVE-2019-25225MEDIUM `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom | Sep 8, 2025 | 6.1 | 22 | NO | NO |
CVE-2014-125128MEDIUM 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in an | Sep 8, 2025 | 6.1 | 21 | NO | NO |
CVE-2026-39857MEDIUM ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the choices and counts query parameter | Apr 15, 2026 | 5.3 | 20 | NO | NO |
CVE-2021-25978MEDIUM Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious JavaScript onto the Images module, which tr | Nov 7, 2021 | 5.4 | 20 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this vendor scope (17 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID that affects a product developed by Apostrophecms.
Media Mentions
Media articles that mention a CVE ID that affects a product developed by Apostrophecms — matched by CVE ID, not by vendor name.