Tag
high
advisory
ApostropheCMS Stored XSS via Image Widget Link (CVE-2026-45011)
2 rulesA stored cross-site scripting vulnerability (CVE-2026-45011) was identified in ApostropheCMS image widget functionality, where a user with the Editor role can configure an image widget link to use a javascript: URL payload, which will execute arbitrary JavaScript in the victim’s browser when clicked.
apostrophecms
xss
cve-2026-45011
javascript
2r
high
advisory
ApostropheCMS Authenticated SSRF via Rich-Text Widget Import (CVE-2026-45012)
2 rulesApostropheCMS is vulnerable to authenticated server-side request forgery (SSRF) via rich-text widget import; an attacker with edit access can trigger server-side requests to attacker-controlled URLs during widget validation, enabling internal port scanning and potential data exfiltration by re-hosting image-compatible responses.
apostrophecms <= 4.29.0
ssrf
apostrophecms
cve-2026-45012
2r