CyberSec.Space Logo
Back to CVE Browser

CVE-2026-44990

CRITICAL
9.3
CVSS Severity Score
EPSS Score0.0600%
EPSS Percentile24.05th
PublishedJun 12, 2026
Last ModifiedJun 12, 2026

Vulnerability Description

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities