Vulnerabilities
Last updated 1 hour ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Ghost: Authorization Bypass in Comments Feature | Medium Risk 6.5 | 3 hours ago | 3 hours ago |
|
|
Ghost: Server-Side Request Forgery in Webhook Trigger | Low Risk 2.7 | 3 hours ago | 3 hours ago |
|
|
Ghost: Path Traversal Vulnerability in Ghost ImageSize Service | Low Risk 3.8 | 3 hours ago | 3 hours ago |
|
|
Ghost vulnerable to information disclosure of private API fields | High Risk 7.5 | 3 years ago | 27 days ago |
|
|
Ghost: Server-Side Request Forgery in Image Fetching | Medium Risk 4.1 | 2 months ago | 1 month ago |
|
|
Ghost: Cross-Site Scripting in Feature Image Captions | Medium Risk 4.3 | 2 months ago | 1 month ago |
|
|
Ghost: Session Fixation in Ghost Admin | Medium Risk 6.7 | 2 months ago | 1 month ago |
|
|
Ghost: Server-Side Request Forgery Mitigation Issue | Medium Risk 4.0 | 2 months ago | 1 month ago |
|
|
Ghost: Cross-Site Scripting in Universal Import | Medium Risk 5.0 | 2 months ago | 1 month ago |
|
|
Ghost: Blind Password Hash Disclosure in Ghost Admin API | Medium Risk 4.8 | 2 months ago | 1 month ago |
|
|
Ghost: Archived Offers can be Redeemed | Medium Risk 4.8 | 2 months ago | 1 month ago |
|
|
Ghost: Theme Upload Path Traversal | Medium Risk 6.6 | 2 months ago | 1 month ago |
|
|
Ghost: Database Backup Path Traversal | Medium Risk 5.5 | 2 months ago | 1 month ago |
|
|
Malicious code in @ghost_debugger/nanocache (npm) | Unknown | 1 month ago | 1 month ago |
|
|
Ghost Content API filter bypass reveals private fields | Medium Risk 5.3 | 2 months ago | 2 months ago |
|
|
Ghost: Member existence leak via magic link sign-in response | Medium Risk 5.3 | 2 months ago | 2 months ago |
|
|
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature | Medium Risk 5.3 | 2 months ago | 2 months ago |
|
|
XSS in Ghost's ActivityPub client | High Risk 7.5 | 2 months ago | 2 months ago |
|
|
Ghost: Server-side request forgery via DNS rebinding in external request handling | Medium Risk 4.0 | 2 months ago | 2 months ago |
|
|
Ghost: Mobiledoc image-size fetch SSRF | Medium Risk 5.4 | 2 months ago | 2 months ago |
|
|
Ghost: Private IP filtering bypass to make server-side requests to internal services | Medium Risk 5.8 | 2 months ago | 2 months ago |
|
|
Ghost: File Upload Content-Type Spoofing | Medium Risk 5.4 | 2 months ago | 2 months ago |
|
|
Malicious code in jmcnevin-rghost-barcode (RubyGems) | Unknown | 2 years ago | 2 months ago |
|
|
Privilege escalation: all users can access Admin-level API keys | Medium Risk 6.5 | 5 years ago | 3 months ago |
|
|
ghost vulnerable to unauthorized newsletter modification via improper access controls | High Risk 8.5 | 3 years ago | 3 months ago |
|
|
DOM XSS in Theme Preview | Medium Risk 6.8 | 5 years ago | 3 months ago |
|
|
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header | Critical 9.6 | 3 months ago | 3 months ago |
|
|
Ghost has a SQL injection in Content API | Critical 9.4 | 7 months ago | 4 months ago |
|
|
Malicious code in gunpowder-ghost (npm) | Unknown | 11 months ago | 5 months ago |
|
|
Malicious code in ghost-module (npm) | Unknown | 6 months ago | 6 months ago |
|
|
Ghost has incomplete CSRF protections around OTC use | High Risk 7.5 | 7 months ago | 7 months ago |
|
|
Ghost Vulnerable to Remote Code Execution via Malicious Themes | High Risk 7.6 | 7 months ago | 7 months ago |
|
|
Ghost vulnerable to XSS via malicious Portal preview links | High Risk 8.8 | 8 months ago | 8 months ago |
|
|
Ghost vulnerable to XSS via malicious Portal preview links | High Risk 8.8 | 8 months ago | 8 months ago |
|
|
Ghost has Staff Token permission bypass | High Risk 8.1 | 9 months ago | 8 months ago |
|
|
Ghost has SQL Injection in Members Activity Feed | Medium Risk 6.7 | 9 months ago | 8 months ago |
|
|
Ghost has Staff 2FA bypass | High Risk 8.1 | 9 months ago | 8 months ago |
|
|
Ghost has SSRF via External Media Inliner | Medium Risk 6.0 | 9 months ago | 8 months ago |
|
|
Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark | Medium Risk 6.0 | 1 year ago | 8 months ago |
|
|
Malicious code in @alexandrsarioglo/npm-ghost-htb (npm) | Unknown | 11 months ago | 11 months ago |
|
|
Malicious code in @dvargas135/gunpowder-ghost (npm) | Unknown | 11 months ago | 11 months ago |
|
|
Malicious code in gunpowder-ghost-curse (npm) | Unknown | 11 months ago | 11 months ago |
|
|
Malicious code in @asarioglo/npm-ghost-htb (npm) | Unknown | 11 months ago | 11 months ago |
|
|
Malicious code in availab-le-alb-um-zip-a-ghost-is-born-fgmfl-kscsps (npm) | Unknown | 1 year ago | 1 year ago |
|
|
Malicious code in gboxghost (npm) | Unknown | 1 year ago | 1 year ago |
|
|
Malicious code in ghostdrop (npm) | Unknown | 1 year ago | 1 year ago |
|
|
Malicious code in ghostlulz-dependency (npm) | Unknown | 1 year ago | 1 year ago |
|
|
Malicious code in ghosts3c (npm) | Unknown | 1 year ago | 1 year ago |
|
|
Ghost allows CSV Injection during member CSV export | High Risk 8.8 | 2 years ago | 1 year ago |
|
|
Ghost's improper authentication allows access to member information and actions | Medium Risk 6.5 | 2 years ago | 1 year ago |
Page 1