Junglewise Threat Intelligence

CVE-2026-45014: ApostropheCMS stored XSS in draft version tooltip

CVE-2026-45014 · Severity: info · CVSS 5.3 · Published 2026-06-12

Technologies: Apostrophe Technologies ApostropheCMS.

Executive brief

ApostropheCMS, a platform used for building and managing websites, contains a security flaw that allows malicious scripts to be saved and executed in the administrative interface. An attacker could use this to target website administrators, potentially leading to unauthorized actions or data theft when the administrator views specific tooltips. At the time of reporting, no official patch has been released.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in ApostropheCMS versions up to and including 4.29.0. The root cause is the failure to sanitize user display names before rendering them within the tooltip of the draft versioning system. An attacker can inject malicious JavaScript into their display name; this script is then executed in the context of any user (typically an editor or admin) who views the affected tooltip. This is a network-based attack requiring user interaction. As of the advisory publication, no patched version is available.

Affected products

  • Apostrophe Technologies ApostropheCMS <= 4.29.0

Timeline

  • 2026-05-13: advisory: Initial GitHub security advisory published
  • 2026-06-12: disclosed: CVE published to NVD

References