Tom Boutell
8 exploits
Active since Jun 2018
ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API
CVSS 5.3
ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
CVSS 3.7
ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API
CVSS 5.3
ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context
CVSS 5.4
ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
CVSS 8.7
Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions
CVSS 5.3
ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements
CVSS 6.1
Punkave Sanitize-html < 1.11.1 - XSS
CVSS 6.1