CVE-2026-53608 - @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
CVE ID :CVE-2026-53608 Published : June 12, 2026, 10:16 p.m. | 51 minutes ago Description :ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`)...