Skip to content
Threat Feed

Tag

Apostrophecms

4 briefs RSS
high advisory

ApostropheCMS Stored XSS via Image Widget Link (CVE-2026-45011)

A stored cross-site scripting vulnerability (CVE-2026-45011) was identified in ApostropheCMS image widget functionality, where a user with the Editor role can configure an image widget link to use a javascript: URL payload, which will execute arbitrary JavaScript in the victim’s browser when clicked.

apostrophecms xss cve-2026-45011 javascript
2r
high advisory

ApostropheCMS Authenticated SSRF via Rich-Text Widget Import (CVE-2026-45012)

ApostropheCMS is vulnerable to authenticated server-side request forgery (SSRF) via rich-text widget import; an attacker with edit access can trigger server-side requests to attacker-controlled URLs during widget validation, enabling internal port scanning and potential data exfiltration by re-hosting image-compatible responses.

apostrophecms <= 4.29.0 ssrf apostrophecms cve-2026-45012
2r
high advisory

ApostropheCMS Stored XSS Vulnerability in SEO Fields Leads to Data Exposure

A stored cross-site scripting (XSS) vulnerability exists in SEO-related fields (SEO Title and Meta Description) in ApostropheCMS v4.28.0, allowing injection of arbitrary JavaScript into HTML contexts, performing authenticated API requests, and exfiltrating sensitive data, leading to a compromise of application confidentiality.

ApostropheCMS xss stored-xss data-exfiltration
2r 5t 1c 2i
high advisory

ApostropheCMS Stored XSS Vulnerability in SEO Fields (CVE-2026-35569)

A stored XSS vulnerability in ApostropheCMS versions 4.28.0 and prior allows attackers to inject arbitrary JavaScript into SEO-related fields, leading to potential data exfiltration and unauthorized actions.

ApostropheCMS xss cve-2026-35569 web-application
2r 2t 1c