Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2026-40186 ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the Apos… Apostrophecms after 2.17.1 Fix from $1,6002026-04-15 HIGH 8.7 CVE-2026-35569 ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in S… Apostrophecms 4.29.0+ Fix from $1,9502026-04-15 MEDIUM 5.3 CVE-2026-39857 ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the cho… Apostrophecms 4.29.0+ Fix from $1,6002026-04-15 MEDIUM 5.4 CVE-2026-33889 ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in t… Apostrophecms 4.29.0+ Fix from $1,6002026-04-15 MEDIUM 5.3 CVE-2026-33888 ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the get… Apostrophecms 4.29.0+ Fix from $1,6002026-04-15 CRITICAL 9.9 CVE-2026-32731 ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `… Import Export 3.5.3+ Fix from $2,3002026-03-18 HIGH 8.1 CVE-2026-32730 ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/… Apostrophecms 4.28.0+ Fix from $1,9502026-03-18 MEDIUM 6.1 CVE-2014-125128 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperref… Sanitize Html 1.0.3+ Fix from $1,6002025-09-08 MEDIUM 6.1 CVE-2019-25225 `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitiz… Sanitize Html 2.0.0+ Fix from $1,6002025-09-08 HIGH 7.5 CVE-2022-25887 The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression repla… Sanitize Html 2.7.1+ Fix from $1,9502022-08-30 CRITICAL 9.8 CVE-2021-25979 Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a … Apostrophecms 3.3.1+ Fix from $2,3002021-11-08 MEDIUM 5.4 CVE-2021-25978 Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious JavaScript o… Apostrophecms after 3.3.1 Fix from $1,6002021-11-07 MEDIUM 5.3 CVE-2021-26539 Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypa… Sanitize Html 2.3.1+ Fix from $1,6002021-02-08 MEDIUM 5.3 CVE-2021-26540 Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allo… Sanitize Html 2.3.2+ Fix from $1,6002021-02-08 MEDIUM 6.1 CVE-2016-1000237 sanitize-html before 1.4.3 has XSS. Sanitize Html 1.4.3+ Fix from $1,6002020-01-23