Stored Cross-Site Scripting in ApostropheCMS Image Widget
CVE-2026-45011

7.3HIGH

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2026-45011?

ApostropheCMS, an open-source Node.js content management system, hosts a stored cross-site scripting vulnerability within its image widget functionality in version 4.29.0. Users assigned the Editor role can configure an image widget link to execute JavaScript via a 'javascript:' URL payload. This allows editors to publish malicious content, which, when clicked by any site visitor—including administrators—results in the execution of arbitrary JavaScript code in their browsers. As of now, there are no known patched versions to resolve this issue, signaling a critical need for immediate attention from users and administrators.

Affected Version(s)

apostrophe = 4.29.0

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.