PatchSiren

APSL CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH APSL CVE published 2026-09-25

CVE-2026-88421

CVE-2026-88421 allows unauthenticated attackers to view restricted blog entries in APSL puput v1.2.1 through v2.2.0 due to incorrect access control in the BlogPage.get_entries() component. This vulnerability impacts defenders responsible for APSL puput instances, particularly those with publicly accessible blog indexes, tags, categories, author and date archives, sidebars, or RSS feeds, as they should ass [truncated]