<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 10:23:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-327331</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-327331</link>
      <description>EUVD-2026-327331</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-327331</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53608</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53608</link>
      <description>&lt;p&gt;ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogleTagManager`) directly into `&amp;lt;script&amp;gt;` tag bodies using JavaScript template literals without any sanitization or validation. Any user with editor-level access (the default role for content managers) can set these fields to a malicious value, resulting in stored XSS that executes on every page for every visitor of the site. As of time of publication, no known patched versions are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogleTagManager`) directly into `&amp;lt;script&amp;gt;` tag bodies using JavaScript template literals without any sanitization or validation. Any user with editor-level access (the default role for content managers) can set these fields to a malicious value, resulting in stored XSS that executes on every page for every visitor of the site. As of time of publication, no known patched versions are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53608</guid>
    </item>
    <item>
      <title>GHSA-wf43-fpp3-cf65 — @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wf43-fpp3-cf65</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @apostrophecms/seo&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1919&amp;#34; height=&amp;#34;1046&amp;#34; alt=&amp;#34;curl&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/8aa19ff1-7f4b-44ee-83d5-d0dd1a0269f6&amp;#34; /&amp;gt;
&amp;lt;img width=&amp;#34;1919&amp;#34; height=&amp;#34;775&amp;#34; alt=&amp;#34;xss&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/a65012e8-9b2f-416f-94df-c00493f2ca1d&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogleTagManager`) directly into `&amp;lt;script&amp;gt;` tag bodies using JavaScript template literals without any sanitization or validation.&lt;/p&gt;
&lt;p&gt;Any user with editor-level access (the default role for content managers) can set these fields to a malicious value, resulting in stored XSS that executes on every page for every visitor of the site.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable code is in `node_modules/@apostrophecms/seo/lib/nodes.js`.&lt;/p&gt;
&lt;p&gt;**Google Analytics (lines 218–224):**&lt;/p&gt;
&lt;p&gt;```javascript
// seoGoogleTrackingId is inserted RAW into a &amp;lt;script&amp;gt; body — no escaping, no validation
body: [ {
  raw: `
  window.dataLayer = window.dataLayer || [];
  function gtag(){dataLayer.push(arguments);}
  gtag(&amp;#39;js&amp;#39;, new Date());
  gtag(&amp;#39;config&amp;#39;, &amp;#39;${global.seoGoogleTrackingId}&amp;#39;);
`
} ]
```&lt;/p&gt;
&lt;p&gt;**Google Tag Manager (lines 358–362):**&lt;/p&gt;
&lt;p&gt;```javascript
body: [ {
  raw: `(function(w,d,s,l,i){...})(window,document,&amp;#39;script&amp;#39;,&amp;#39;dataLayer&amp;#39;,&amp;#39;${global.seoGoogleTagManager}&amp;#39;);`
} ]
```&lt;/p&gt;
&lt;p&gt;These nodes are rendered by `renderNodes()` in ApostropheCMS core (`modules/@apostrophecms/template/index.js` lines 1176–1177):&lt;/p&gt;
&lt;p&gt;```javascript
if (node.r…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @apostrophecms/seo&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1919&amp;#34; height=&amp;#34;1046&amp;#34; alt=&amp;#34;curl&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/8aa19ff1-7f4b-44ee-83d5-d0dd1a0269f6&amp;#34; /&amp;gt;
&amp;lt;img width=&amp;#34;1919&amp;#34; height=&amp;#34;775&amp;#34; alt=&amp;#34;xss&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/a65012e8-9b2f-416f-94df-c00493f2ca1d&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogleTagManager`) directly into `&amp;lt;script&amp;gt;` tag bodies using JavaScript template literals without any sanitization or validation.&lt;/p&gt;
&lt;p&gt;Any user with editor-level access (the default role for content managers) can set these fields to a malicious value, resulting in stored XSS that executes on every page for every visitor of the site.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable code is in `node_modules/@apostrophecms/seo/lib/nodes.js`.&lt;/p&gt;
&lt;p&gt;**Google Analytics (lines 218–224):**&lt;/p&gt;
&lt;p&gt;```javascript
// seoGoogleTrackingId is inserted RAW into a &amp;lt;script&amp;gt; body — no escaping, no validation
body: [ {
  raw: `
  window.dataLayer = window.dataLayer || [];
  function gtag(){dataLayer.push(arguments);}
  gtag(&amp;#39;js&amp;#39;, new Date());
  gtag(&amp;#39;config&amp;#39;, &amp;#39;${global.seoGoogleTrackingId}&amp;#39;);
`
} ]
```&lt;/p&gt;
&lt;p&gt;**Google Tag Manager (lines 358–362):**&lt;/p&gt;
&lt;p&gt;```javascript
body: [ {
  raw: `(function(w,d,s,l,i){...})(window,document,&amp;#39;script&amp;#39;,&amp;#39;dataLayer&amp;#39;,&amp;#39;${global.seoGoogleTagManager}&amp;#39;);`
} ]
```&lt;/p&gt;
&lt;p&gt;These nodes are rendered by `renderNodes()` in ApostropheCMS core (`modules/@apostrophecms/template/index.js` lines 1176–1177):&lt;/p&gt;
&lt;p&gt;```javascript
if (node.r…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wf43-fpp3-cf65</guid>
    </item>
  </channel>
</rss>
