{"api_version":"v1","generated_at":"2026-10-08T00:10:00+00:00","product":{"cve_count":18,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-apostrophecms-apostrophe-65a8a9284a97","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/apostrophe","name":"apostrophe","next_cursor":null,"observations":[{"affected":">= 1.9.0, < 2.17.7","affected_versions_present":true,"cve_id":"CVE-2026-84371","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84371","fixed":"2.17.7.","last_modified":"2026-09-02T16:02:13.385Z","patch_url":"https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-g8qq-57p8-ggw5","primary_source":"","published":"2026-09-01T20:51:10.441Z"},{"affected":"<= 4.32.0","affected_versions_present":true,"cve_id":"CVE-2026-71553","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-71553","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-17T20:14:15.721Z","patch_url":"","primary_source":"","published":"2026-08-17T20:03:37.883Z"},{"affected":"< 3.6.2","affected_versions_present":true,"cve_id":"CVE-2026-63667","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63667","fixed":"3.6.2.","last_modified":"2026-08-17T20:05:42.231Z","patch_url":"https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-79qf-vqgc-7xx3","primary_source":"","published":"2026-08-17T19:56:07.436Z"},{"affected":"< 2.17.6","affected_versions_present":true,"cve_id":"CVE-2026-63670","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63670","fixed":"2.17.6.","last_modified":"2026-08-18T18:08:30.331Z","patch_url":"https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-jxwj-j7wr-gfrw","primary_source":"","published":"2026-08-17T19:49:51.903Z"},{"affected":"< 4.32.0","affected_versions_present":true,"cve_id":"CVE-2026-63669","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63669","fixed":"4.32.0.","last_modified":"2026-08-17T22:01:18.244Z","patch_url":"https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-wr5r-wqp2-x4fh","primary_source":"","published":"2026-08-17T19:41:52.574Z"},{"affected":"<= 4.30.0","affected_versions_present":true,"cve_id":"CVE-2026-53609","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53609","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-15T18:29:55.055Z","patch_url":"","primary_source":"","published":"2026-06-12T20:59:25.486Z"},{"affected":"<= 4.30.0","affected_versions_present":true,"cve_id":"CVE-2026-53607","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53607","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-15T18:35:34.721Z","patch_url":"","primary_source":"","published":"2026-06-12T20:54:30.866Z"},{"affected":"<= 4.29.0","affected_versions_present":true,"cve_id":"CVE-2026-45014","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45014","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-15T17:55:54.492Z","patch_url":"","primary_source":"","published":"2026-06-12T20:48:32.921Z"},{"affected":"<= 4.29.0","affected_versions_present":true,"cve_id":"CVE-2026-45013","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45013","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-13T03:37:07.486Z","patch_url":"","primary_source":"","published":"2026-06-12T20:46:21.628Z"},{"affected":"<= 4.29.0","affected_versions_present":true,"cve_id":"CVE-2026-45012","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45012","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-15T19:27:52.986Z","patch_url":"","primary_source":"","published":"2026-06-12T20:44:48.842Z"},{"affected":"= 4.29.0","affected_versions_present":true,"cve_id":"CVE-2026-45011","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45011","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-15T15:16:38.776Z","patch_url":"","primary_source":"","published":"2026-06-12T20:43:18.939Z"},{"affected":">= 4.28.0, < 4.29.0; >= 2.17.1, < 2.17.2","affected_versions_present":true,"cve_id":"CVE-2026-40186","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40186","fixed":"2.17.2","last_modified":"2026-04-16T14:15:41.275Z","patch_url":"https://github.com/apostrophecms/apostrophe/commit/7ca2d16237c72718ef7e5c7ae0458e6027ac4f64","primary_source":"","published":"2026-04-15T20:15:12.333Z"},{"affected":"< 4.29.0","affected_versions_present":true,"cve_id":"CVE-2026-39857","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39857","fixed":"4.29.0.","last_modified":"2026-04-16T13:40:17.710Z","patch_url":"https://github.com/apostrophecms/apostrophe/commit/6c2b548dec2e3f7a82e8e16736603f4cd17525aa","primary_source":"","published":"2026-04-15T19:38:57.564Z"},{"affected":"< 4.29.0","affected_versions_present":true,"cve_id":"CVE-2026-35569","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35569","fixed":"4.29.0.","last_modified":"2026-05-14T16:07:20.897Z","patch_url":"https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-855c-r2vq-c292","primary_source":"","published":"2026-04-15T19:34:23.648Z"},{"affected":"< 4.29.0","affected_versions_present":true,"cve_id":"CVE-2026-33889","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33889","fixed":"4.29.0.","last_modified":"2026-04-16T12:05:17.734Z","patch_url":"https://github.com/apostrophecms/apostrophe/commit/6a89bdb7acdb2e1e9bf1429961a6ba7f99410481","primary_source":"","published":"2026-04-15T19:29:50.899Z"},{"affected":"< 4.29.0","affected_versions_present":true,"cve_id":"CVE-2026-33888","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33888","fixed":"4.29.0.","last_modified":"2026-04-15T20:03:30.594Z","patch_url":"https://github.com/apostrophecms/apostrophe/commit/00d472804bb622df36a761b6f2cf2b33b2d4ce80","primary_source":"","published":"2026-04-15T19:25:46.262Z"},{"affected":"< 4.29.0","affected_versions_present":true,"cve_id":"CVE-2026-33877","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33877","fixed":"4.29.0.","last_modified":"2026-04-15T19:30:53.040Z","patch_url":"https://github.com/apostrophecms/apostrophe/commit/e266cffd8c0d331a9b05c92bf11616556efcdc77","primary_source":"","published":"2026-04-15T19:11:06.796Z"},{"affected":"< 4.28.0","affected_versions_present":true,"cve_id":"CVE-2026-32730","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32730","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-19T16:12:15.179Z","patch_url":"","primary_source":"","published":"2026-03-18T22:00:14.612Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"apostrophecms"}}
