What is CVE-2026-63670?
A vulnerability in ApostropheCMS versions prior to 2.17.6 allows the sanitizeHtml() function to pass disallowed executable markup when 'textarea' or 'xmp' tags are included in the allowedTags list, due to improper handling of the raw-text end-tag. This could lead to XSS attacks. Users should immediately upgrade to version 2.17.6 or later.
Azərbaycanca: ApostropheCMS-in 2.17.6-dan əvvəlki versiyalarında sanitizeHtml() funksiyası, 'textarea' və 'xmp' teqləri icazəli siyahıda olduqda, zərərli kodun (executable markup) süzgəcdən keçməsinə imkan verən boşluq aşkarlanıb. Bu zəiflik istifadəçi tərəfindən daxil edilən məlumatın düzgün təmizlənməməsi səbəbindən XSS hücumlarına yol aça bilər. ApostropheCMS istifadəçiləri təcili olaraq 2.17.6 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which function in ApostropheCMS contains a vulnerability that could lead to an XSS attack?
The vulnerability was found in the sanitizeHtml() function of ApostropheCMS. This function can pass disallowed executable markup when 'textarea' or 'xmp' tags are in the allowed list, potentially leading to XSS attacks.
To which version should ApostropheCMS users upgrade to fix the CVE-2026-63670 vulnerability?
Users should immediately upgrade to ApostropheCMS version 2.17.6 or later. This version addresses the vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.