CVE-2026-35569Disclosure(apostrophecms / apostrophecms)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apostrophecms apostrophecms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in SEO-related fields (SEO Title and Meta Description), where user-controlled input is rendered without proper output encoding into HTML contexts including <title> tags, <meta> attributes, and JSON-LD structured data. An attacker can inject a payload such as "></title><script>alert(1)</script> to break out of the intended HTML context and execute arbitrary JavaScript in the browser of any authenticated user who views the affected page. This can be leveraged to perform authenticated API requests, access sensitive data such as usernames, email addresses, and roles via internal APIs, and exfiltrate it to an attacker-controlled server. This issue has been fixed in version 4.29.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-116

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apostrophecms

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-16); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
apostrophecms

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-16: 1Mentions · 2026-05-02: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-04-16: 1Technical Details · 2026-05-02: 104-1605-02
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-161
Disclosure1
2026-05-021
Patch1
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    ApostropheCMS CVE-2026-35569: Stored XSS in SEO fields. Low-priv attacker injects `"&gt;&lt;/title&gt;`, exfils users/emails/roles via API. CVSS 8.7. Patch to 4.29.0 now. #XSS #DevSecOps #CVE #DevOps #infosec #cyebrsecurity #hackers #100daysofhacking Info: https://www.valtersit.com/cve/2026/04/cve-2026-35569/

    Post summary

    The post reports a stored XSS vulnerability (CVE‑2026‑35569) in ApostropheCMS with a CVSS of 8.7, and notes that patch 4.29.0 is now available.

    0000043
    889 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35569 ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in SEO-related fields… https://www.cve.org/CVERecord?id=CVE-2026-35569

    Post summary

    The text announces CVE-2026-35569, identifying a stored XSS flaw in older versions of ApostropheCMS’s SEO fields.

    00000100
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapostrophecmsapostrophecms---

Explore more