Skip to content
Threat Feed

Vendor

ApostropheCMS

4 briefs RSS
high advisory

Stored XSS Vulnerability in @apostrophecms/seo

An authenticated Stored XSS vulnerability in the @apostrophecms/seo package (CVE-2026-53608) allows editors to inject malicious JavaScript into script tags, enabling session theft and unauthorized code execution for all site visitors.

@apostrophecms/seo
1r 2t 1c
critical advisory

ApostropheCMS Server-Side Prototype Pollution via apos.util.set

A server-side prototype pollution vulnerability in ApostropheCMS allows an authenticated editor to bypass authorization for all subsequent API requests by polluting Object.prototype via the $pullAll patch operator.

ApostropheCMS
1r 1t 1c
high advisory

ApostropheCMS Stored XSS Vulnerability in SEO Fields Leads to Data Exposure

A stored cross-site scripting (XSS) vulnerability exists in SEO-related fields (SEO Title and Meta Description) in ApostropheCMS v4.28.0, allowing injection of arbitrary JavaScript into HTML contexts, performing authenticated API requests, and exfiltrating sensitive data, leading to a compromise of application confidentiality.

ApostropheCMS xss stored-xss data-exfiltration
2r 5t 1c 2i
high advisory

ApostropheCMS Stored XSS Vulnerability in SEO Fields (CVE-2026-35569)

A stored XSS vulnerability in ApostropheCMS versions 4.28.0 and prior allows attackers to inject arbitrary JavaScript into SEO-related fields, leading to potential data exfiltration and unauthorized actions.

ApostropheCMS xss cve-2026-35569 web-application
2r 2t 1c