CVE-2026-44990General

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-06-14)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-19: 1Mentions · 2026-06-14: 2Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-19: 105-1906-14
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-191
Patch1
2026-06-142
General2
Full discourse3 posts
  • antony.dev@antony_oti
    Patch

    Just shipped my first open source security contribution 🔐. I ran a Trivy SAST scan on @formbricks, found a CRITICAL stored XSS vulnerability (CVE-2026-44990, CVSS 9.3), reproduced it locally, and opened a PR with the fix. Here's the full breakdown:

    Post summary

    The tweet announces the identification of a critical stored XSS vulnerability, provides its technical details, and notes that a fix is being merged via a pull request.

    5000091
    61 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-44990 ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuratio… https://www.cve.org/CVERecord?id=CVE-2026-44990 ----- Traducción: CVE-2026-44990 Apo… http://infoflow.cloud`

    Post summary

    The post merely references CVE-2026-44990 and links to its official record, without providing any details on exploitation, solutions, or PoC.

    0000031
    79 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-44990 ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuratio… https://www.cve.org/CVERecord?id=CVE-2026-44990

    Post summary

    The passage merely references CVE-2026-44990 without providing additional technical, exploit, or mitigation details.

    00000238
    57.6K followersView on X

Explore more