Executive brief
ApostropheCMS is a content management system used to build and manage websites. A vulnerability in its SEO configuration fields allows attackers to inject malicious JavaScript code that executes in the browsers of authenticated administrators. When an admin visits a page with the injected code, their browser automatically sends sensitive user data—including email addresses, usernames, and admin roles—to attacker-controlled servers, compromising the confidentiality of application data.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in ApostropheCMS SEO-related fields (SEO Title and Meta Description) due to improper neutralization of user input before rendering into HTML contexts including <title>, <meta> attributes, and JSON-LD structured data. An authenticated user with page-edit privileges can inject arbitrary JavaScript by escaping the HTML context using payloads like `"></title><script>...</script>`. The injected script executes with the privileges of any authenticated user (including administrators) who views the compromised page, enabling session riding attacks that exfiltrate sensitive data via the `/api/v1/@apostrophecms/user` API endpoint. The vulnerability affects ApostropheCMS versions up to and including 4.28.0 and is patched in version 4.29.0. Attack requires user interaction (victim must visit the page) and prior authentication, but the impact is high due to confidentiality and integrity implications.
Affected products
- ApostropheCMS Apostrophe <= 4.28.0
Timeline
- 2026-04-15: disclosed
- 2026-04-16: patched: Version 4.29.0