Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Apostrophecms MEDIUM 6.1
CVE-2026-40186

ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the Apos…

Fix: after 2.17.1
Fix from $1,600 2026-04-15
Apostrophecms HIGH 8.7
CVE-2026-35569

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in S…

Fix: 4.29.0+
Fix from $1,950 2026-04-15
Apostrophecms MEDIUM 5.3
CVE-2026-39857

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the cho…

Fix: 4.29.0+
Fix from $1,600 2026-04-15
Apostrophecms MEDIUM 5.4
CVE-2026-33889

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in t…

Fix: 4.29.0+
Fix from $1,600 2026-04-15
Apostrophecms MEDIUM 5.3
CVE-2026-33888

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the get…

Fix: 4.29.0+
Fix from $1,600 2026-04-15
Import Export CRITICAL 9.9
CVE-2026-32731

ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `…

Fix: 3.5.3+
Fix from $2,300 2026-03-18
Apostrophecms HIGH 8.1
CVE-2026-32730

ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/…

Fix: 4.28.0+
Fix from $1,950 2026-03-18
Sanitize Html MEDIUM 6.1
CVE-2014-125128

'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperref…

Fix: 1.0.3+
Fix from $1,600 2025-09-08
Sanitize Html MEDIUM 6.1
CVE-2019-25225

`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitiz…

Fix: 2.0.0+
Fix from $1,600 2025-09-08
Sanitize Html HIGH 7.5
CVE-2022-25887

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression repla…

Fix: 2.7.1+
Fix from $1,950 2022-08-30
Apostrophecms CRITICAL 9.8
CVE-2021-25979

Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a …

Fix: 3.3.1+
Fix from $2,300 2021-11-08
Apostrophecms MEDIUM 5.4
CVE-2021-25978

Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious JavaScript o…

Fix: after 3.3.1
Fix from $1,600 2021-11-07
Sanitize Html MEDIUM 5.3
CVE-2021-26539

Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypa…

Fix: 2.3.1+
Fix from $1,600 2021-02-08
Sanitize Html MEDIUM 5.3
CVE-2021-26540

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allo…

Fix: 2.3.2+
Fix from $1,600 2021-02-08
Sanitize Html MEDIUM 6.1
CVE-2016-1000237

sanitize-html before 1.4.3 has XSS.

Fix: 1.4.3+
Fix from $1,600 2020-01-23