npm

apostrophe

View on npm registry
17 Total advisories
17 Vulnerabilities
0 Malware

Dependency scanning

Check whether apostrophe is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 6.5
npm

CVE-2026-63669

ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree

UNKNOWN
npm

CVE-2026-71553

ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS

LOW 3.7
npm

CVE-2026-53607

@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header

CRITICAL 9.1
npm

CVE-2026-53609

Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass

HIGH 8.1
npm

CVE-2026-45013

Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation

HIGH 7.3
npm

CVE-2026-45011

Apostrophe has stored XSS via javascript: URL in Image Widget Link

HIGH 7.6
npm

CVE-2026-45012

Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget

HIGH 8.7
npm

CVE-2026-35569

Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS

MEDIUM 5.3
npm

CVE-2026-33888

ApostropheCMS: publicApiProjection Bypass via project Query Builder in Piece-Type REST API

LOW 3.7
npm

CVE-2026-33877

ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint

MEDIUM 5.4
npm

CVE-2026-33889

ApostropheCMS: Stored XSS via CSS Custom Property Injection in @apostrophecms/color-field Escaping Style Tag Context

MEDIUM 5.3
npm

CVE-2026-39857

ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions

HIGH 8.1
npm

CVE-2026-32730

ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware

CRITICAL 9.8
npm

CVE-2021-25979

Apostrophe CMS Insufficient Session Expiration vulnerability

MEDIUM 5.4
npm

CVE-2021-25978

Cross-site Scripting in apostrophe

UNKNOWN
npm

GHSA-h97g-4mx7-5p2p

Open Redirect in apostrophe

UNKNOWN
npm

GHSA-pv6r-vchh-cxg9

Denial of Service in apostrophe

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes