Ghost records
34 published records for vendor ghost.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 5.9%
- Pre-auth RCE
- 4
- With a fix record
- 67.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-453 Insecure Default Variable Initialization4
- CWE-918 Server-Side Request Forgery (SSRF)3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-284 Improper Access Control2
- CWE-287 Improper Authentication2
The weakness classes this vendor ships most often: where to look.
CWEAll records
34 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2023-40028Proof of concept | Arbitrary file read via symlinks in Ghostghost · ghost · CWE-22 | Medium6.5 | — | 68.7% | Aug 15, 2023 |
44Plan | CVE-2023-31133No exploit | Ghost vulnerable to disclosure of private API fieldsghost · ghost · CWE-200 | High7.5 | — | 45.7% | May 8, 2023 |
42Plan | CVE-2023-32235Proof of concept | Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directoghost · ghost · CWE-22 | High7.5 | — | 39.1% | May 5, 2023 |
40Plan | CVE-2026-29053Weaponized | Ghost Vulnerable to Remote Code Execution via Malicious Themesghost · ghost · CWE-74 | Critical9.8 | — | 4.8% | Mar 5, 2026 |
40Plan | CVE-2022-27139No exploit | An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted Sghost · ghost · CWE-434 | Critical9.8 | — | 4.0% | Apr 12, 2022 |
40Plan | CVE-2022-28397No exploit | An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a craftghost · ghost · CWE-434 | Critical9.8 | — | 3.5% | Apr 12, 2022 |
40Plan | CVE-2022-43441No exploit | A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1.ghost · sqlite3 · CWE-915 | Critical9.8 | — | 2.4% | Mar 16, 2023 |
37Monitor | CVE-2024-23724Proof of concept | Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profghost · ghost · CWE-79 | Critical9.0 | — | 3.5% | Feb 10, 2024 |
36Monitor | CVE-2024-34451No exploit | Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headeghost · ghost · CWE-1390 | Critical9.1 | — | 0.8% | Jun 16, 2024 |
35Monitor | CVE-2024-34448No exploit | Ghost before 5.82.0 allows CSV Injection during a member CSV export.ghost · ghost · CWE-74 | High8.8 | — | 0.7% | May 22, 2024 |
35Monitor | CVE-2026-29784No exploit | Ghost: Incomplete CSRF protections around OTC useghost · ghost · CWE-352 | High8.8 | — | 0.2% | Mar 7, 2026 |
32Monitor | CVE-2026-22594Weaponized | Ghost has Staff 2FA bypassghost · ghost · CWE-287 | High8.1 | — | 1.3% | Jan 9, 2026 |
32Monitor | CVE-2020-8134No exploit | Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise intghost · ghost · CWE-918 | High8.1 | — | 1.2% | Mar 20, 2020 |
32Monitor | CVE-2026-22595No exploit | Ghost has Staff Token permission bypassghost · ghost · CWE-863 | High8.1 | — | 0.5% | Jan 9, 2026 |
31Monitor | CVE-2026-26980Proof of concept | Ghost has a SQL Injection in its Content APIghost · ghost · CWE-89 | High7.5 | — | 5.0% | Feb 19, 2026 |
31Monitor | CVE-2022-21227No exploit | Denial of Service (DoS)ghost · sqlite3 | High7.5 | — | 2.2% | May 1, 2022 |
30Monitor | CVE-2024-34559No exploit | WordPress Ghost plugin <= 1.4.0 - Sensitive Data Exposure via Log File vulnerabilityghost foundation · ghost · CWE-532 | High7.5 | — | 0.7% | May 14, 2024 |
29Monitor | CVE-2021-29484Proof of concept | DOM XSS in Theme Previewghost · ghost · CWE-79 | Medium6.8 | — | 7.9% | Apr 29, 2021 |
28Monitor | CVE-2021-39192No exploit | Privilege escalation: all users can access Admin-level API keysghost · ghost · CWE-200 | High7.2 | — | 1.0% | Sep 3, 2021 |
28Monitor | CVE-2026-22596No exploit | Ghost has SQL Injection in Members Activity Feedghost · ghost · CWE-89 | High7.2 | — | 0.5% | Jan 9, 2026 |
27Monitor | CVE-2022-41697Proof of concept | A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-204 | Medium5.3 | — | 20.0% | Dec 22, 2022 |
26Monitor | CVE-2016-10983No exploit | The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.ghost · ghost · CWE-287 | Medium6.5 | — | 1.5% | Sep 17, 2019 |
26Monitor | CVE-2024-43409No exploit | Ghost's improper authentication allows access to member information and actionsghost · ghost · CWE-284 | Medium6.5 | — | 0.3% | Aug 20, 2024 |
24Monitor | CVE-2025-9862No exploit | Ghost 6.0.6 - SSRF via oEmbed Bookmarkghost · ghost · CWE-918 | Medium6.1 | — | 0.5% | Sep 17, 2025 |
24Monitor | CVE-2024-23725No exploit | Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js.ghost · ghost · CWE-79 | Medium6.1 | — | 0.4% | Jan 21, 2024 |
- CVE-2023-4002847Plan
Arbitrary file read via symlinks in Ghost
MediumCVSS 6.5Proof of conceptEPSS 69%ghost · ghostAug 15, 2023
- CVE-2023-3113344Plan
Ghost vulnerable to disclosure of private API fields
HighCVSS 7.5No exploitEPSS 46%ghost · ghostMay 8, 2023
- CVE-2023-3223542Plan
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directo
HighCVSS 7.5Proof of conceptEPSS 39%ghost · ghostMay 5, 2023
- CVE-2026-2905340Plan
Ghost Vulnerable to Remote Code Execution via Malicious Themes
CriticalCVSS 9.8WeaponizedEPSS 5%ghost · ghostMar 5, 2026
- CVE-2022-2713940Plan
An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted S
CriticalCVSS 9.8No exploitEPSS 4%ghost · ghostApr 12, 2022
- CVE-2022-2839740Plan
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a craft
CriticalCVSS 9.8No exploitEPSS 3%ghost · ghostApr 12, 2022
- CVE-2022-4344140Plan
A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1.
CriticalCVSS 9.8No exploitEPSS 2%ghost · sqlite3Mar 16, 2023
- CVE-2024-2372437Monitor
Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG prof
CriticalCVSS 9.0Proof of conceptEPSS 3%ghost · ghostFeb 10, 2024
- CVE-2024-3445136Monitor
Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For heade
CriticalCVSS 9.1No exploitEPSS 1%ghost · ghostJun 16, 2024
- CVE-2024-3444835Monitor
Ghost before 5.82.0 allows CSV Injection during a member CSV export.
HighCVSS 8.8No exploitEPSS 1%ghost · ghostMay 22, 2024
- CVE-2026-2978435Monitor
Ghost: Incomplete CSRF protections around OTC use
HighCVSS 8.8No exploitEPSS 0%ghost · ghostMar 7, 2026
- CVE-2026-2259432Monitor
Ghost has Staff 2FA bypass
HighCVSS 8.1WeaponizedEPSS 1%ghost · ghostJan 9, 2026
- CVE-2020-813432Monitor
Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise int
HighCVSS 8.1No exploitEPSS 1%ghost · ghostMar 20, 2020
- CVE-2026-2259532Monitor
Ghost has Staff Token permission bypass
HighCVSS 8.1No exploitEPSS 1%ghost · ghostJan 9, 2026
- CVE-2026-2698031Monitor
Ghost has a SQL Injection in its Content API
HighCVSS 7.5Proof of conceptEPSS 5%ghost · ghostFeb 19, 2026
- CVE-2022-2122731Monitor
Denial of Service (DoS)
HighCVSS 7.5No exploitEPSS 2%ghost · sqlite3May 1, 2022
- CVE-2024-3455930Monitor
WordPress Ghost plugin <= 1.4.0 - Sensitive Data Exposure via Log File vulnerability
HighCVSS 7.5No exploitEPSS 1%ghost foundation · ghostMay 14, 2024
- CVE-2021-2948429Monitor
DOM XSS in Theme Preview
MediumCVSS 6.8Proof of conceptEPSS 8%ghost · ghostApr 29, 2021
- CVE-2021-3919228Monitor
Privilege escalation: all users can access Admin-level API keys
HighCVSS 7.2No exploitEPSS 1%ghost · ghostSep 3, 2021
- CVE-2026-2259628Monitor
Ghost has SQL Injection in Members Activity Feed
HighCVSS 7.2No exploitEPSS 0%ghost · ghostJan 9, 2026
- CVE-2022-4169727Monitor
A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4.
MediumCVSS 5.3Proof of conceptEPSS 20%ghost · ghostDec 22, 2022
- CVE-2016-1098326Monitor
The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.
MediumCVSS 6.5No exploitEPSS 2%ghost · ghostSep 17, 2019
- CVE-2024-4340926Monitor
Ghost's improper authentication allows access to member information and actions
MediumCVSS 6.5No exploitEPSS 0%ghost · ghostAug 20, 2024
- CVE-2025-986224Monitor
Ghost 6.0.6 - SSRF via oEmbed Bookmark
MediumCVSS 6.1No exploitEPSS 1%ghost · ghostSep 17, 2025
- CVE-2024-2372524Monitor
Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js.
MediumCVSS 6.1No exploitEPSS 0%ghost · ghostJan 21, 2024