← العودة للجدول
CVE-2026-53608
CVE-2026-53608 — ApostropheCMS is an open-source Node.js content management system. Versions up t
📅 2026-06-12
🟠 High 🔥 No NVD ICS/OT OT/ICS CVSS 8.7

📋 الوصف الكامل

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogleTagManager`) directly into `` tag bodies using JavaScript template literals without any sanitization or validation. Any user with editor-level access (the defau

💻 الأنظمة المتأثرة

Node.js

⚠️ نوع التهديد

ICS/OT

🔗 CVE ID

CVE-2026-53608

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v1.4.2

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←