Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2630▼ 215 respecto a la semana anterior
Críticas / altas1379▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.30% | — | Sanitize-htmlAIApostrophecmsAI | 1/9/2026 | 9/9/2026 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting… | |
| Aplazada | Alta (7.1) | 0.43% | — | ApostrophecmsAI | 17/8/2026 | 9/9/2026 | ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility module to apos.util.set() and apos.util.get(), allowing an authenticated editor to overwrite the shared… | |
| Aplazada | Media (6.1) | 0.33% | — | ApostrophecmsAI | 17/8/2026 | 9/9/2026 | ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a literal solidus after the raw-text end-tag name is treated as text by htmlparser2… | |
| Aplazada | Media (6.5) | 0.31% | — | ApostrophecmsAI | 17/8/2026 | 9/9/2026 | ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission because its oldParent archive condition disables the check for ordinary moves, allowing an authenticated editor or contributor to use… | |
| Aplazada | Media (6.5) | 0.46% | — | ApostrophecmsAI | 17/8/2026 | 9/9/2026 | ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip.js constructs an attachment source path from the attacker-controlled _id, name, and extension fields in aposAttachments.json without ensuring that the resolved path… | |
| Aplazada | Crítica (9.1) | 0.38% | — | ApostrophecmsAI | 12/6/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.prototype` via the `$pullAll` patch operator. A confirmed… | |
| Aplazada | Alta (8.7) | 0.35% | — | Apostrophecms SEOAI | 12/6/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogleTagManager`) directly into `<script>` tag bodies using JavaScript template… | |
| Aplazada | Baja (3.7) | 0.32% | — | ApostrophecmsAINodejsAI | 12/6/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyUrls: true` is enabled on `@apostrophecms/file` (a documented SEO feature for serving uploaded files at clean URLs), the public pretty-URL handler builds the upstream URL using the raw `Host` HTTP… | |
| Aplazada | Media (5.4) | 0.23% | — | ApostrophecmsAISanitize-htmlAI | 12/6/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Versions of sanitize-html prior to 2.17.5 use `allowedSchemesAppliedToAttributes` (default: `['href', 'src', 'cite']`) to gate the `naughtyHref()` function that blocks dangerous URI… | |
| Aplazada | Media (5.3) | 0.44% | — | ApostrophecmsAI | 12/6/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 are vulnerable to stored cross-site scripting via unsanitized user display name in draft version tooltip. As of time of publication, no known patched versions are available. | |
| Aplazada | Alta (8.1) | 0.38% | — | ApostrophecmsAI | 12/6/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password reset flow that constructs the reset URL using `req.hostname`, which is derived directly from the attacker-controlled HTTP `Host` header when `apos.baseUrl` is not explicitly configured. An… | |
| Aplazada | Alta (7.6) | 0.31% | — | ApostrophecmsAI | 12/6/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authenticated server-side request forgery (SSRF) in the rich-text widget import flow. An authenticated user who can submit/edit rich-text widget content can cause the server to fetch attacker-controlled… | |
| Aplazada | Alta (7.3) | 0.37% | — | ApostrophecmsAI | 12/6/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vulnerability in the image widget functionality. A user with the Editor role can configure an image widget link to use a javascript: URL payload. Because editors have permission to publish pages, the… | |
| Aplazada | Crítica (9.3) | 0.69% | — | ApostrophecmsAISanitize-htmlAI | 12/6/2026 | 10/9/2026 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This… | |
| Aplazada | Media (6.5) | 0.62% | — | Apostrophecms CLIAI | 12/6/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and including 3.6.0 contain a command injection vulnerability in the apos create command. User-supplied input from the password prompt is embedded directly into a shell command without proper… | |
| Analizada | Media (6.1) | 0.28% | — | ApostrophecmsApostrophecms Sanitize-html | 15/4/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the ApostropheCMS-maintained sanitize-html package bypasses allowedTags enforcement for text inside nonTextTagsArray elements (textarea and option). ApostropheCMS version 4.28.0… | |
| Analizada | Media (5.3) | 0.38% | — | Apostrophecms | 15/4/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the choices and counts query parameters of the REST API, where these query builders execute MongoDB distinct() operations that bypass the publicApiProjection restrictions… | |
| Modificada | Alta (8.7) | 0.44% | — | Apostrophecms | 15/4/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in SEO-related fields (SEO Title and Meta Description), where user-controlled input is rendered without proper output encoding into HTML contexts including <title> tags,… | |
| Analizada | Media (5.4) | 0.26% | — | Apostrophecms | 15/4/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in the @apostrophecms/color-field module, where color values prefixed with -- bypass TinyColor validation intended for CSS custom properties, and the launder.string() call… | |
| Analizada | Media (5.3) | 0.52% | — | Apostrophecms | 15/4/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the getRestQuery method of the @apostrophecms/piece-type module, where the method checks whether a MongoDB projection has already been set before applying the admin-configured… | |
| Analizada | Baja (3.7) | 0.32% | — | Apostrophecms | 15/4/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-channel vulnerability in the password reset endpoint (/api/v1/@apostrophecms/login/reset-request) that allows unauthenticated username and email enumeration. When a user is not found, the handler returns… | |
| Analizada | Crítica (9.9) | 0.59% | — | Apostrophecms Import-export | 18/3/2026 | 17/6/2026 | ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` constructs file-write paths using `fs.createWriteStream(path.join(exportPath, header.name))`. `path.join()` does not resolve or sanitise traversal segments such… | |
| Analizada | Alta (8.1) | 0.48% | — | Apostrophecms | 18/3/2026 | 17/6/2026 | ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/index.js` (lines 386-389) contains an incorrect MongoDB query that allows incomplete login tokens — where the password was verified but TOTP/MFA requirements were… | |
| Analizada | Media (6.1) | 0.27% | — | Apostrophecms Sanitize-html | 8/9/2025 | 17/6/2026 | 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in anchor tags (`<a>`), allowing bypasses that contain different casings, whitespace characters, or hexadecimal encodings. | |
| Analizada | Media (6.1) | 0.27% | — | Apostrophecms Sanitize-html | 8/9/2025 | 17/6/2026 | `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into… |