← العودة للجدول
CVE-2026-44990
CVE-2026-44990 — ApostropheCMS is an open-source Node.js content management system, and sanitize-
📅 2026-06-12
🔴 Critical 🔥 No NVD Exploit Web CVSS 9.3 🎯 EPSS 0.06%

📋 الوصف الكامل

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` pa

💻 الأنظمة المتأثرة

Node.js

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-44990

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v2.17.4

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←