Vulnerability Details CVE-2021-25978
Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious JavaScript onto the Images module, which triggers XSS once viewed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.1%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2021-25978
-
cpe:2.3:a:apostrophecms:apostrophecms:2.100.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.100.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.100.2
-
cpe:2.3:a:apostrophecms:apostrophecms:2.101.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.101.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.102.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.102.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.102.2
-
cpe:2.3:a:apostrophecms:apostrophecms:2.102.3
-
cpe:2.3:a:apostrophecms:apostrophecms:2.102.4
-
cpe:2.3:a:apostrophecms:apostrophecms:2.102.5
-
cpe:2.3:a:apostrophecms:apostrophecms:2.103.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.103.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.104.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.105.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.105.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.105.2
-
cpe:2.3:a:apostrophecms:apostrophecms:2.106.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.106.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.106.2
-
cpe:2.3:a:apostrophecms:apostrophecms:2.107.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.107.2
-
cpe:2.3:a:apostrophecms:apostrophecms:2.111.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.111.3
-
cpe:2.3:a:apostrophecms:apostrophecms:2.111.4
-
cpe:2.3:a:apostrophecms:apostrophecms:2.111.5
-
cpe:2.3:a:apostrophecms:apostrophecms:2.112.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.112.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.113.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.113.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.113.2
-
cpe:2.3:a:apostrophecms:apostrophecms:2.113.3
-
cpe:2.3:a:apostrophecms:apostrophecms:2.114.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.115.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.115.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.116.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.116.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.117.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.117.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.118.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.119.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.119.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.220.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.220.2
-
cpe:2.3:a:apostrophecms:apostrophecms:2.220.3
-
cpe:2.3:a:apostrophecms:apostrophecms:2.220.4
-
cpe:2.3:a:apostrophecms:apostrophecms:2.220.5
-
cpe:2.3:a:apostrophecms:apostrophecms:2.220.6
-
cpe:2.3:a:apostrophecms:apostrophecms:2.220.7
-
cpe:2.3:a:apostrophecms:apostrophecms:2.63.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.64.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.64.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.65.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.66.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.67.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.68.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.68.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.69.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.69.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.70.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.70.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.71.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.71.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.72.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.72.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.72.2
-
cpe:2.3:a:apostrophecms:apostrophecms:2.72.3
-
cpe:2.3:a:apostrophecms:apostrophecms:2.73.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.74.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.75.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.75.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.76.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.76.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.77.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.77.2
-
cpe:2.3:a:apostrophecms:apostrophecms:2.78.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.79.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.80.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.81.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.81.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.81.2
-
cpe:2.3:a:apostrophecms:apostrophecms:2.82.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.83.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.83.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.84.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.84.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.85.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.86.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.87.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.88.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.88.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.89.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.89.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.90.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.91.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.92.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.92.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.93.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.94.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.94.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.95.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.95.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.96.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.96.2
-
cpe:2.3:a:apostrophecms:apostrophecms:2.97.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.97.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.97.2
-
cpe:2.3:a:apostrophecms:apostrophecms:2.98.0
-
cpe:2.3:a:apostrophecms:apostrophecms:2.98.1
-
cpe:2.3:a:apostrophecms:apostrophecms:2.99.0
-
cpe:2.3:a:apostrophecms:apostrophecms:3.0.0
-
cpe:2.3:a:apostrophecms:apostrophecms:3.0.1
-
cpe:2.3:a:apostrophecms:apostrophecms:3.1.0
-
cpe:2.3:a:apostrophecms:apostrophecms:3.1.1
-
cpe:2.3:a:apostrophecms:apostrophecms:3.1.2
-
cpe:2.3:a:apostrophecms:apostrophecms:3.1.3
-
cpe:2.3:a:apostrophecms:apostrophecms:3.2.0
-
cpe:2.3:a:apostrophecms:apostrophecms:3.3.0
-
cpe:2.3:a:apostrophecms:apostrophecms:3.3.1