ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 are vulnerable to stored cross-site scripting via unsanitized user display name in draft version tooltip. As of time of publication, no known patched versions are available.
CVSS
No CVSS.
References
Configurations
No configuration.
History
12 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-12 21:16
Updated : 2026-06-15 20:54
NVD link : CVE-2026-45014
Mitre link : CVE-2026-45014
CVE.ORG link : CVE-2026-45014
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
