Stored Cross-Site Scripting Vulnerability in ApostropheCMS by Apostrophe
CVE-2026-45014

5.3MEDIUM

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2026-45014?

ApostropheCMS, an open-source Node.js content management system, is susceptible to stored cross-site scripting attacks in versions up to and including 4.29.0. This vulnerability arises from unsanitized user display names in the draft version tooltip, potentially allowing attackers to execute malicious scripts in the context of other users. As of now, there are no patches available for this issue, making it critical for users to implement immediate mitigation strategies.

Affected Version(s)

apostrophe <= 4.29.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.