VYPR

Apostrophe

by Apostrophecms

npm: apostrophe

Source repositories

CVEs (24)

  • CVE-2026-39857MedApr 15, 2026
    risk 0.27cvss 5.3epss 0.00

    ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the choices and counts query parameters of the REST API, where these query builders execute MongoDB distinct() operations that bypass the…

  • CVE-2026-33888MedApr 15, 2026
    risk 0.27cvss 5.3epss 0.01

    ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the getRestQuery method of the @apostrophecms/piece-type module, where the method checks whether a MongoDB projection has already been…

  • CVE-2026-53607LowJun 12, 2026
    risk 0.17cvss 3.7epss 0.00

    ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyUrls: true` is enabled on `@apostrophecms/file` (a documented SEO feature for serving uploaded files at clean URLs), the public pretty-URL handler builds the…

  • CVE-2026-33877LowApr 15, 2026
    risk 0.17cvss 3.7epss 0.00

    ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-channel vulnerability in the password reset endpoint (/api/v1/@apostrophecms/login/reset-request) that allows unauthenticated username and email enumeration. When a…

Page 2 of 2