Vulnerabilities (CVE)

Filtered by vendor Apostrophecms Subscribe
Filtered by product Apostrophecms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25978 1 Apostrophecms 1 Apostrophecms 2021-11-09 3.5 LOW 5.4 MEDIUM
Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious JavaScript onto the Images module, which triggers XSS once viewed.