Security Advisories for apostrophe in npm
Low
15 days ago
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
npm
apostrophe
Critical
15 days ago
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
npm
apostrophe
High
3 months ago
Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation
npm
apostrophe
High
3 months ago
Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget
npm
apostrophe
Moderate
4 months ago
ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions
npm
apostrophe
High
4 months ago
Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
npm
apostrophe
Moderate
4 months ago
ApostropheCMS: Stored XSS via CSS Custom Property Injection in @apostrophecms/color-field Escaping Style Tag Context
npm
apostrophe
Moderate
4 months ago
ApostropheCMS: publicApiProjection Bypass via project Query Builder in Piece-Type REST API
npm
apostrophe
Low
4 months ago
ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
npm
apostrophe
High
5 months ago
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
npm
apostrophe
Critical
almost 5 years ago
Apostrophe CMS Insufficient Session Expiration vulnerability
npm
apostrophe