Записи Ghost
34 опубликованных записей вендора ghost.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 5,9 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 67,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-453 Insecure Default Variable Initialization4
- CWE-918 Server-Side Request Forgery (SSRF)3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-284 Improper Access Control2
- CWE-287 Improper Authentication2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
34 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
47В плане | CVE-2023-40028Proof of concept | Arbitrary file read via symlinks in Ghostghost · ghost · CWE-22 | Средняя6,5 | — | 68,7 % | 15 авг. 2023 г. |
44В плане | CVE-2023-31133Эксплойта нет | Ghost vulnerable to disclosure of private API fieldsghost · ghost · CWE-200 | Высокая7,5 | — | 45,7 % | 8 мая 2023 г. |
42В плане | CVE-2023-32235Proof of concept | Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directoghost · ghost · CWE-22 | Высокая7,5 | — | 39,1 % | 5 мая 2023 г. |
40В плане | CVE-2026-29053Готовый эксплойт | Ghost Vulnerable to Remote Code Execution via Malicious Themesghost · ghost · CWE-74 | Критическая9,8 | — | 4,8 % | 5 мар. 2026 г. |
40В плане | CVE-2022-27139Эксплойта нет | An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted Sghost · ghost · CWE-434 | Критическая9,8 | — | 4,0 % | 12 апр. 2022 г. |
40В плане | CVE-2022-28397Эксплойта нет | An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a craftghost · ghost · CWE-434 | Критическая9,8 | — | 3,5 % | 12 апр. 2022 г. |
40В плане | CVE-2022-43441Эксплойта нет | A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1.ghost · sqlite3 · CWE-915 | Критическая9,8 | — | 2,4 % | 16 мар. 2023 г. |
37Наблюдать | CVE-2024-23724Proof of concept | Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profghost · ghost · CWE-79 | Критическая9,0 | — | 3,5 % | 10 февр. 2024 г. |
36Наблюдать | CVE-2024-34451Эксплойта нет | Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headeghost · ghost · CWE-1390 | Критическая9,1 | — | 0,8 % | 16 июн. 2024 г. |
35Наблюдать | CVE-2024-34448Эксплойта нет | Ghost before 5.82.0 allows CSV Injection during a member CSV export.ghost · ghost · CWE-74 | Высокая8,8 | — | 0,7 % | 22 мая 2024 г. |
35Наблюдать | CVE-2026-29784Эксплойта нет | Ghost: Incomplete CSRF protections around OTC useghost · ghost · CWE-352 | Высокая8,8 | — | 0,2 % | 7 мар. 2026 г. |
32Наблюдать | CVE-2026-22594Готовый эксплойт | Ghost has Staff 2FA bypassghost · ghost · CWE-287 | Высокая8,1 | — | 1,3 % | 9 янв. 2026 г. |
32Наблюдать | CVE-2020-8134Эксплойта нет | Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise intghost · ghost · CWE-918 | Высокая8,1 | — | 1,2 % | 20 мар. 2020 г. |
32Наблюдать | CVE-2026-22595Эксплойта нет | Ghost has Staff Token permission bypassghost · ghost · CWE-863 | Высокая8,1 | — | 0,5 % | 9 янв. 2026 г. |
31Наблюдать | CVE-2026-26980Proof of concept | Ghost has a SQL Injection in its Content APIghost · ghost · CWE-89 | Высокая7,5 | — | 5,0 % | 19 февр. 2026 г. |
31Наблюдать | CVE-2022-21227Эксплойта нет | Denial of Service (DoS)ghost · sqlite3 | Высокая7,5 | — | 2,2 % | 1 мая 2022 г. |
30Наблюдать | CVE-2024-34559Эксплойта нет | WordPress Ghost plugin <= 1.4.0 - Sensitive Data Exposure via Log File vulnerabilityghost foundation · ghost · CWE-532 | Высокая7,5 | — | 0,7 % | 14 мая 2024 г. |
29Наблюдать | CVE-2021-29484Proof of concept | DOM XSS in Theme Previewghost · ghost · CWE-79 | Средняя6,8 | — | 7,9 % | 29 апр. 2021 г. |
28Наблюдать | CVE-2021-39192Эксплойта нет | Privilege escalation: all users can access Admin-level API keysghost · ghost · CWE-200 | Высокая7,2 | — | 1,0 % | 3 сент. 2021 г. |
28Наблюдать | CVE-2026-22596Эксплойта нет | Ghost has SQL Injection in Members Activity Feedghost · ghost · CWE-89 | Высокая7,2 | — | 0,5 % | 9 янв. 2026 г. |
27Наблюдать | CVE-2022-41697Proof of concept | A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-204 | Средняя5,3 | — | 20,0 % | 22 дек. 2022 г. |
26Наблюдать | CVE-2016-10983Эксплойта нет | The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.ghost · ghost · CWE-287 | Средняя6,5 | — | 1,5 % | 17 сент. 2019 г. |
26Наблюдать | CVE-2024-43409Эксплойта нет | Ghost's improper authentication allows access to member information and actionsghost · ghost · CWE-284 | Средняя6,5 | — | 0,3 % | 20 авг. 2024 г. |
24Наблюдать | CVE-2025-9862Эксплойта нет | Ghost 6.0.6 - SSRF via oEmbed Bookmarkghost · ghost · CWE-918 | Средняя6,1 | — | 0,5 % | 17 сент. 2025 г. |
24Наблюдать | CVE-2024-23725Эксплойта нет | Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js.ghost · ghost · CWE-79 | Средняя6,1 | — | 0,4 % | 21 янв. 2024 г. |
- CVE-2023-4002847В плане
Arbitrary file read via symlinks in Ghost
СредняяCVSS 6,5Proof of conceptEPSS 69 %ghost · ghost15 авг. 2023 г.
- CVE-2023-3113344В плане
Ghost vulnerable to disclosure of private API fields
ВысокаяCVSS 7,5Эксплойта нетEPSS 46 %ghost · ghost8 мая 2023 г.
- CVE-2023-3223542В плане
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directo
ВысокаяCVSS 7,5Proof of conceptEPSS 39 %ghost · ghost5 мая 2023 г.
- CVE-2026-2905340В плане
Ghost Vulnerable to Remote Code Execution via Malicious Themes
КритическаяCVSS 9,8Готовый эксплойтEPSS 5 %ghost · ghost5 мар. 2026 г.
- CVE-2022-2713940В плане
An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted S
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %ghost · ghost12 апр. 2022 г.
- CVE-2022-2839740В плане
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a craft
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ghost · ghost12 апр. 2022 г.
- CVE-2022-4344140В плане
A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ghost · sqlite316 мар. 2023 г.
- CVE-2024-2372437Наблюдать
Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG prof
КритическаяCVSS 9,0Proof of conceptEPSS 3 %ghost · ghost10 февр. 2024 г.
- CVE-2024-3445136Наблюдать
Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For heade
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %ghost · ghost16 июн. 2024 г.
- CVE-2024-3444835Наблюдать
Ghost before 5.82.0 allows CSV Injection during a member CSV export.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ghost · ghost22 мая 2024 г.
- CVE-2026-2978435Наблюдать
Ghost: Incomplete CSRF protections around OTC use
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %ghost · ghost7 мар. 2026 г.
- CVE-2026-2259432Наблюдать
Ghost has Staff 2FA bypass
ВысокаяCVSS 8,1Готовый эксплойтEPSS 1 %ghost · ghost9 янв. 2026 г.
- CVE-2020-813432Наблюдать
Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise int
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %ghost · ghost20 мар. 2020 г.
- CVE-2026-2259532Наблюдать
Ghost has Staff Token permission bypass
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %ghost · ghost9 янв. 2026 г.
- CVE-2026-2698031Наблюдать
Ghost has a SQL Injection in its Content API
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %ghost · ghost19 февр. 2026 г.
- CVE-2022-2122731Наблюдать
Denial of Service (DoS)
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ghost · sqlite31 мая 2022 г.
- CVE-2024-3455930Наблюдать
WordPress Ghost plugin <= 1.4.0 - Sensitive Data Exposure via Log File vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ghost foundation · ghost14 мая 2024 г.
- CVE-2021-2948429Наблюдать
DOM XSS in Theme Preview
СредняяCVSS 6,8Proof of conceptEPSS 8 %ghost · ghost29 апр. 2021 г.
- CVE-2021-3919228Наблюдать
Privilege escalation: all users can access Admin-level API keys
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %ghost · ghost3 сент. 2021 г.
- CVE-2026-2259628Наблюдать
Ghost has SQL Injection in Members Activity Feed
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %ghost · ghost9 янв. 2026 г.
- CVE-2022-4169727Наблюдать
A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4.
СредняяCVSS 5,3Proof of conceptEPSS 20 %ghost · ghost22 дек. 2022 г.
- CVE-2016-1098326Наблюдать
The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %ghost · ghost17 сент. 2019 г.
- CVE-2024-4340926Наблюдать
Ghost's improper authentication allows access to member information and actions
СредняяCVSS 6,5Эксплойта нетEPSS 0 %ghost · ghost20 авг. 2024 г.
- CVE-2025-986224Наблюдать
Ghost 6.0.6 - SSRF via oEmbed Bookmark
СредняяCVSS 6,1Эксплойта нетEPSS 1 %ghost · ghost17 сент. 2025 г.
- CVE-2024-2372524Наблюдать
Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %ghost · ghost21 янв. 2024 г.