Skip to content
Noroxi

Ghost records

34 published records for vendor ghost.

Researcher profile

Entered KEV
0 · 0%
Weaponized
2 · 5.9%
Pre-auth RCE
4
With a fix record
67.6%
Median publish → KEV
No record has entered KEV

All records

34 records
  • Arbitrary file read via symlinks in Ghost

    MediumCVSS 6.5Proof of conceptEPSS 69%

    ghost · ghostAug 15, 2023

  • Ghost vulnerable to disclosure of private API fields

    HighCVSS 7.5No exploitEPSS 46%

    ghost · ghostMay 8, 2023

  • Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directo

    HighCVSS 7.5Proof of conceptEPSS 39%

    ghost · ghostMay 5, 2023

  • Ghost Vulnerable to Remote Code Execution via Malicious Themes

    CriticalCVSS 9.8WeaponizedEPSS 5%

    ghost · ghostMar 5, 2026

  • An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted S

    CriticalCVSS 9.8No exploitEPSS 4%

    ghost · ghostApr 12, 2022

  • An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a craft

    CriticalCVSS 9.8No exploitEPSS 3%

    ghost · ghostApr 12, 2022

  • A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1.

    CriticalCVSS 9.8No exploitEPSS 2%

    ghost · sqlite3Mar 16, 2023

  • Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG prof

    CriticalCVSS 9.0Proof of conceptEPSS 3%

    ghost · ghostFeb 10, 2024

  • Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For heade

    CriticalCVSS 9.1No exploitEPSS 1%

    ghost · ghostJun 16, 2024

  • Ghost before 5.82.0 allows CSV Injection during a member CSV export.

    HighCVSS 8.8No exploitEPSS 1%

    ghost · ghostMay 22, 2024

  • Ghost: Incomplete CSRF protections around OTC use

    HighCVSS 8.8No exploitEPSS 0%

    ghost · ghostMar 7, 2026

  • Ghost has Staff 2FA bypass

    HighCVSS 8.1WeaponizedEPSS 1%

    ghost · ghostJan 9, 2026

  • CVE-2020-8134
    32Monitor

    Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise int

    HighCVSS 8.1No exploitEPSS 1%

    ghost · ghostMar 20, 2020

  • Ghost has Staff Token permission bypass

    HighCVSS 8.1No exploitEPSS 1%

    ghost · ghostJan 9, 2026

  • Ghost has a SQL Injection in its Content API

    HighCVSS 7.5Proof of conceptEPSS 5%

    ghost · ghostFeb 19, 2026

  • Denial of Service (DoS)

    HighCVSS 7.5No exploitEPSS 2%

    ghost · sqlite3May 1, 2022

  • WordPress Ghost plugin <= 1.4.0 - Sensitive Data Exposure via Log File vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    ghost foundation · ghostMay 14, 2024

  • DOM XSS in Theme Preview

    MediumCVSS 6.8Proof of conceptEPSS 8%

    ghost · ghostApr 29, 2021

  • Privilege escalation: all users can access Admin-level API keys

    HighCVSS 7.2No exploitEPSS 1%

    ghost · ghostSep 3, 2021

  • Ghost has SQL Injection in Members Activity Feed

    HighCVSS 7.2No exploitEPSS 0%

    ghost · ghostJan 9, 2026

  • A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4.

    MediumCVSS 5.3Proof of conceptEPSS 20%

    ghost · ghostDec 22, 2022

  • The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.

    MediumCVSS 6.5No exploitEPSS 2%

    ghost · ghostSep 17, 2019

  • Ghost's improper authentication allows access to member information and actions

    MediumCVSS 6.5No exploitEPSS 0%

    ghost · ghostAug 20, 2024

  • CVE-2025-9862
    24Monitor

    Ghost 6.0.6 - SSRF via oEmbed Bookmark

    MediumCVSS 6.1No exploitEPSS 1%

    ghost · ghostSep 17, 2025

  • Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js.

    MediumCVSS 6.1No exploitEPSS 0%

    ghost · ghostJan 21, 2024