17 Total advisories
17 Vulnerabilities
0 Malware
Dependency scanning
Check whether apostrophe is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.5
CVE-2026-63669
ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
UNKNOWN
CVE-2026-71553
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
LOW 3.7
CVE-2026-53607
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
CRITICAL 9.1
CVE-2026-53609
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
HIGH 8.1
CVE-2026-45013
Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation
HIGH 7.3
CVE-2026-45011
Apostrophe has stored XSS via javascript: URL in Image Widget Link
HIGH 7.6
CVE-2026-45012
Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget
HIGH 8.7
CVE-2026-35569
Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
MEDIUM 5.3
CVE-2026-33888
ApostropheCMS: publicApiProjection Bypass via project Query Builder in Piece-Type REST API
LOW 3.7
CVE-2026-33877
ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
MEDIUM 5.4
CVE-2026-33889
ApostropheCMS: Stored XSS via CSS Custom Property Injection in @apostrophecms/color-field Escaping Style Tag Context
MEDIUM 5.3
CVE-2026-39857
ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions
HIGH 8.1
CVE-2026-32730
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
CRITICAL 9.8
CVE-2021-25979
Apostrophe CMS Insufficient Session Expiration vulnerability
MEDIUM 5.4
CVE-2021-25978
Cross-site Scripting in apostrophe
UNKNOWN
GHSA-h97g-4mx7-5p2p
Open Redirect in apostrophe
UNKNOWN
GHSA-pv6r-vchh-cxg9
Denial of Service in apostrophe
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes