Ghost kayıtları
ghost üreticisine ait 34 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %5,9
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %67,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-453 Insecure Default Variable Initialization4
- CWE-918 Server-Side Request Forgery (SSRF)3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-284 Improper Access Control2
- CWE-287 Improper Authentication2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
34 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
47Planlayın | CVE-2023-40028Kavram kanıtı | Arbitrary file read via symlinks in Ghostghost · ghost · CWE-22 | Orta6,5 | — | %68,7 | 15 Ağu 2023 |
44Planlayın | CVE-2023-31133İstismar yok | Ghost vulnerable to disclosure of private API fieldsghost · ghost · CWE-200 | Yüksek7,5 | — | %45,7 | 8 May 2023 |
42Planlayın | CVE-2023-32235Kavram kanıtı | Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directoghost · ghost · CWE-22 | Yüksek7,5 | — | %39,1 | 5 May 2023 |
40Planlayın | CVE-2026-29053Silahlaştırılmış | Ghost Vulnerable to Remote Code Execution via Malicious Themesghost · ghost · CWE-74 | Kritik9,8 | — | %4,8 | 5 Mar 2026 |
40Planlayın | CVE-2022-27139İstismar yok | An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted Sghost · ghost · CWE-434 | Kritik9,8 | — | %4,0 | 12 Nis 2022 |
40Planlayın | CVE-2022-28397İstismar yok | An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a craftghost · ghost · CWE-434 | Kritik9,8 | — | %3,5 | 12 Nis 2022 |
40Planlayın | CVE-2022-43441İstismar yok | A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1.ghost · sqlite3 · CWE-915 | Kritik9,8 | — | %2,4 | 16 Mar 2023 |
37İzleyin | CVE-2024-23724Kavram kanıtı | Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profghost · ghost · CWE-79 | Kritik9,0 | — | %3,5 | 10 Şub 2024 |
36İzleyin | CVE-2024-34451İstismar yok | Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headeghost · ghost · CWE-1390 | Kritik9,1 | — | %0,8 | 16 Haz 2024 |
35İzleyin | CVE-2024-34448İstismar yok | Ghost before 5.82.0 allows CSV Injection during a member CSV export.ghost · ghost · CWE-74 | Yüksek8,8 | — | %0,7 | 22 May 2024 |
35İzleyin | CVE-2026-29784İstismar yok | Ghost: Incomplete CSRF protections around OTC useghost · ghost · CWE-352 | Yüksek8,8 | — | %0,2 | 7 Mar 2026 |
32İzleyin | CVE-2026-22594Silahlaştırılmış | Ghost has Staff 2FA bypassghost · ghost · CWE-287 | Yüksek8,1 | — | %1,3 | 9 Oca 2026 |
32İzleyin | CVE-2020-8134İstismar yok | Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise intghost · ghost · CWE-918 | Yüksek8,1 | — | %1,2 | 20 Mar 2020 |
32İzleyin | CVE-2026-22595İstismar yok | Ghost has Staff Token permission bypassghost · ghost · CWE-863 | Yüksek8,1 | — | %0,5 | 9 Oca 2026 |
31İzleyin | CVE-2026-26980Kavram kanıtı | Ghost has a SQL Injection in its Content APIghost · ghost · CWE-89 | Yüksek7,5 | — | %5,0 | 19 Şub 2026 |
31İzleyin | CVE-2022-21227İstismar yok | Denial of Service (DoS)ghost · sqlite3 | Yüksek7,5 | — | %2,2 | 1 May 2022 |
30İzleyin | CVE-2024-34559İstismar yok | WordPress Ghost plugin <= 1.4.0 - Sensitive Data Exposure via Log File vulnerabilityghost foundation · ghost · CWE-532 | Yüksek7,5 | — | %0,7 | 14 May 2024 |
29İzleyin | CVE-2021-29484Kavram kanıtı | DOM XSS in Theme Previewghost · ghost · CWE-79 | Orta6,8 | — | %7,9 | 29 Nis 2021 |
28İzleyin | CVE-2021-39192İstismar yok | Privilege escalation: all users can access Admin-level API keysghost · ghost · CWE-200 | Yüksek7,2 | — | %1,0 | 3 Eyl 2021 |
28İzleyin | CVE-2026-22596İstismar yok | Ghost has SQL Injection in Members Activity Feedghost · ghost · CWE-89 | Yüksek7,2 | — | %0,5 | 9 Oca 2026 |
27İzleyin | CVE-2022-41697Kavram kanıtı | A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-204 | Orta5,3 | — | %20,0 | 22 Ara 2022 |
26İzleyin | CVE-2016-10983İstismar yok | The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.ghost · ghost · CWE-287 | Orta6,5 | — | %1,5 | 17 Eyl 2019 |
26İzleyin | CVE-2024-43409İstismar yok | Ghost's improper authentication allows access to member information and actionsghost · ghost · CWE-284 | Orta6,5 | — | %0,3 | 20 Ağu 2024 |
24İzleyin | CVE-2025-9862İstismar yok | Ghost 6.0.6 - SSRF via oEmbed Bookmarkghost · ghost · CWE-918 | Orta6,1 | — | %0,5 | 17 Eyl 2025 |
24İzleyin | CVE-2024-23725İstismar yok | Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js.ghost · ghost · CWE-79 | Orta6,1 | — | %0,4 | 21 Oca 2024 |
- CVE-2023-4002847Planlayın
Arbitrary file read via symlinks in Ghost
OrtaCVSS 6,5Kavram kanıtıEPSS %69ghost · ghost15 Ağu 2023
- CVE-2023-3113344Planlayın
Ghost vulnerable to disclosure of private API fields
YüksekCVSS 7,5İstismar yokEPSS %46ghost · ghost8 May 2023
- CVE-2023-3223542Planlayın
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directo
YüksekCVSS 7,5Kavram kanıtıEPSS %39ghost · ghost5 May 2023
- CVE-2026-2905340Planlayın
Ghost Vulnerable to Remote Code Execution via Malicious Themes
KritikCVSS 9,8SilahlaştırılmışEPSS %5ghost · ghost5 Mar 2026
- CVE-2022-2713940Planlayın
An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted S
KritikCVSS 9,8İstismar yokEPSS %4ghost · ghost12 Nis 2022
- CVE-2022-2839740Planlayın
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a craft
KritikCVSS 9,8İstismar yokEPSS %3ghost · ghost12 Nis 2022
- CVE-2022-4344140Planlayın
A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1.
KritikCVSS 9,8İstismar yokEPSS %2ghost · sqlite316 Mar 2023
- CVE-2024-2372437İzleyin
Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG prof
KritikCVSS 9,0Kavram kanıtıEPSS %3ghost · ghost10 Şub 2024
- CVE-2024-3445136İzleyin
Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For heade
KritikCVSS 9,1İstismar yokEPSS %1ghost · ghost16 Haz 2024
- CVE-2024-3444835İzleyin
Ghost before 5.82.0 allows CSV Injection during a member CSV export.
YüksekCVSS 8,8İstismar yokEPSS %1ghost · ghost22 May 2024
- CVE-2026-2978435İzleyin
Ghost: Incomplete CSRF protections around OTC use
YüksekCVSS 8,8İstismar yokEPSS %0ghost · ghost7 Mar 2026
- CVE-2026-2259432İzleyin
Ghost has Staff 2FA bypass
YüksekCVSS 8,1SilahlaştırılmışEPSS %1ghost · ghost9 Oca 2026
- CVE-2020-813432İzleyin
Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise int
YüksekCVSS 8,1İstismar yokEPSS %1ghost · ghost20 Mar 2020
- CVE-2026-2259532İzleyin
Ghost has Staff Token permission bypass
YüksekCVSS 8,1İstismar yokEPSS %1ghost · ghost9 Oca 2026
- CVE-2026-2698031İzleyin
Ghost has a SQL Injection in its Content API
YüksekCVSS 7,5Kavram kanıtıEPSS %5ghost · ghost19 Şub 2026
- CVE-2022-2122731İzleyin
Denial of Service (DoS)
YüksekCVSS 7,5İstismar yokEPSS %2ghost · sqlite31 May 2022
- CVE-2024-3455930İzleyin
WordPress Ghost plugin <= 1.4.0 - Sensitive Data Exposure via Log File vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1ghost foundation · ghost14 May 2024
- CVE-2021-2948429İzleyin
DOM XSS in Theme Preview
OrtaCVSS 6,8Kavram kanıtıEPSS %8ghost · ghost29 Nis 2021
- CVE-2021-3919228İzleyin
Privilege escalation: all users can access Admin-level API keys
YüksekCVSS 7,2İstismar yokEPSS %1ghost · ghost3 Eyl 2021
- CVE-2026-2259628İzleyin
Ghost has SQL Injection in Members Activity Feed
YüksekCVSS 7,2İstismar yokEPSS %0ghost · ghost9 Oca 2026
- CVE-2022-4169727İzleyin
A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4.
OrtaCVSS 5,3Kavram kanıtıEPSS %20ghost · ghost22 Ara 2022
- CVE-2016-1098326İzleyin
The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.
OrtaCVSS 6,5İstismar yokEPSS %2ghost · ghost17 Eyl 2019
- CVE-2024-4340926İzleyin
Ghost's improper authentication allows access to member information and actions
OrtaCVSS 6,5İstismar yokEPSS %0ghost · ghost20 Ağu 2024
- CVE-2025-986224İzleyin
Ghost 6.0.6 - SSRF via oEmbed Bookmark
OrtaCVSS 6,1İstismar yokEPSS %1ghost · ghost17 Eyl 2025
- CVE-2024-2372524İzleyin
Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js.
OrtaCVSS 6,1İstismar yokEPSS %0ghost · ghost21 Oca 2024