apostrophe
9 known vulnerabilities · 1 critical · 0 high
Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions
Apostrophe CMS Insufficient Session Expiration vulnerability
ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
ApostropheCMS: Stored XSS via CSS Custom Property Injection in @apostrophecms/color-field Escaping Style Tag Context
ApostropheCMS: publicApiProjection Bypass via project Query Builder in Piece-Type REST API
ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction