Vulnerabilidades em apostrophecms

23 resultados
Análise Vexday

ApostropheCMS apresenta 18 vulnerabilidades catalogadas, com 10 delas publicadas nos últimos 90 dias, indicando atividade recente significativa. Embora nenhuma vulnerabilidade esteja sob exploração ativa confirmada (KEV), 3 são críticas e a fraqueza dominante é XSS (CWE-79), típica de plataformas de conteúdo, representando risco de comprometimento de sessões e dados de usuários. A cadência elevada de descobertas recentes recomenda monitoramento contínuo e aplicação de patches prioritários nas versões em produção.

CVE-2026-44990CRITICALApostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`EPSS 0.7%CVE-2026-42853MEDIUM@apostrophecms/cli: Command Injection in apos create via Unsanitized Password InputEPSS 0.6%CVE-2026-32731CRITICALApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip ExtractionEPSS 0.6%CVE-2026-33888MEDIUMApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST APIEPSS 0.5%CVE-2026-32730HIGHApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token MiddlewareEPSS 0.5%CVE-2026-63667MEDIUMApostropheCMS: Arbitrary file read via import-export attachment-name path traversalEPSS 0.5%CVE-2026-45014MEDIUMApostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Display Name in Draft Version TooltipEPSS 0.4%CVE-2026-35569HIGHApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMSEPSS 0.4%CVE-2026-71553HIGHApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoSEPSS 0.4%CVE-2026-39857MEDIUMInformation Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field RestrictionsEPSS 0.4%CVE-2026-53609CRITICALApostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypassEPSS 0.4%CVE-2026-45013HIGHApostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input ValidationEPSS 0.4%CVE-2026-45011HIGHApostrophe has stored XSS via javascript: URL in Image Widget LinkEPSS 0.4%CVE-2026-53608HIGH@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script TagEPSS 0.4%CVE-2026-63670MEDIUMApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus closeEPSS 0.3%CVE-2026-33877LOWApostropheCMS: User Enumeration via Timing Side Channel in Password Reset EndpointEPSS 0.3%CVE-2026-53607LOW@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host headerEPSS 0.3%CVE-2026-63669MEDIUMApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtreeEPSS 0.3%CVE-2026-45012HIGHApostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widgetEPSS 0.3%CVE-2026-84371MEDIUMApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypassEPSS 0.3%