Vulnerabilities

Last updated 1 hour ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
ghost Ghost: Authorization Bypass in Comments Feature Medium Risk 6.5 3 hours ago 3 hours ago
ghost Ghost: Server-Side Request Forgery in Webhook Trigger Low Risk 2.7 3 hours ago 3 hours ago
ghost Ghost: Path Traversal Vulnerability in Ghost ImageSize Service Low Risk 3.8 3 hours ago 3 hours ago
ghost Ghost vulnerable to information disclosure of private API fields High Risk 7.5 3 years ago 27 days ago
ghost Ghost: Server-Side Request Forgery in Image Fetching Medium Risk 4.1 2 months ago 1 month ago
ghost Ghost: Cross-Site Scripting in Feature Image Captions Medium Risk 4.3 2 months ago 1 month ago
ghost Ghost: Session Fixation in Ghost Admin Medium Risk 6.7 2 months ago 1 month ago
ghost Ghost: Server-Side Request Forgery Mitigation Issue Medium Risk 4.0 2 months ago 1 month ago
ghost Ghost: Cross-Site Scripting in Universal Import Medium Risk 5.0 2 months ago 1 month ago
ghost Ghost: Blind Password Hash Disclosure in Ghost Admin API Medium Risk 4.8 2 months ago 1 month ago
ghost Ghost: Archived Offers can be Redeemed Medium Risk 4.8 2 months ago 1 month ago
ghost Ghost: Theme Upload Path Traversal Medium Risk 6.6 2 months ago 1 month ago
ghost Ghost: Database Backup Path Traversal Medium Risk 5.5 2 months ago 1 month ago
@ghost_debugger/nanocache Malicious code in @ghost_debugger/nanocache (npm) Unknown 1 month ago 1 month ago
ghost Ghost Content API filter bypass reveals private fields Medium Risk 5.3 2 months ago 2 months ago
ghost Ghost: Member existence leak via magic link sign-in response Medium Risk 5.3 2 months ago 2 months ago
ghost Ghost: Paid gift memberships obtainable at minimal cost via the donations feature Medium Risk 5.3 2 months ago 2 months ago
@tryghost/activitypub XSS in Ghost's ActivityPub client High Risk 7.5 2 months ago 2 months ago
ghost Ghost: Server-side request forgery via DNS rebinding in external request handling Medium Risk 4.0 2 months ago 2 months ago
ghost Ghost: Mobiledoc image-size fetch SSRF Medium Risk 5.4 2 months ago 2 months ago
ghost Ghost: Private IP filtering bypass to make server-side requests to internal services Medium Risk 5.8 2 months ago 2 months ago
ghost Ghost: File Upload Content-Type Spoofing Medium Risk 5.4 2 months ago 2 months ago
jmcnevin-rghost-barcode Malicious code in jmcnevin-rghost-barcode (RubyGems) Unknown 2 years ago 2 months ago
ghost Privilege escalation: all users can access Admin-level API keys Medium Risk 6.5 5 years ago 3 months ago
ghost ghost vulnerable to unauthorized newsletter modification via improper access controls High Risk 8.5 3 years ago 3 months ago
ghost DOM XSS in Theme Preview Medium Risk 6.8 5 years ago 3 months ago
ghost Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header Critical 9.6 3 months ago 3 months ago
ghost Ghost has a SQL injection in Content API Critical 9.4 7 months ago 4 months ago
gunpowder-ghost Malicious code in gunpowder-ghost (npm) Unknown 11 months ago 5 months ago
ghost-module Malicious code in ghost-module (npm) Unknown 6 months ago 6 months ago
ghost Ghost has incomplete CSRF protections around OTC use High Risk 7.5 7 months ago 7 months ago
ghost Ghost Vulnerable to Remote Code Execution via Malicious Themes High Risk 7.6 7 months ago 7 months ago
ghost Ghost vulnerable to XSS via malicious Portal preview links High Risk 8.8 8 months ago 8 months ago
@tryghost/portal Ghost vulnerable to XSS via malicious Portal preview links High Risk 8.8 8 months ago 8 months ago
ghost Ghost has Staff Token permission bypass High Risk 8.1 9 months ago 8 months ago
ghost Ghost has SQL Injection in Members Activity Feed Medium Risk 6.7 9 months ago 8 months ago
ghost Ghost has Staff 2FA bypass High Risk 8.1 9 months ago 8 months ago
ghost Ghost has SSRF via External Media Inliner Medium Risk 6.0 9 months ago 8 months ago
ghost Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark Medium Risk 6.0 1 year ago 8 months ago
@alexandrsarioglo/npm-ghost-htb Malicious code in @alexandrsarioglo/npm-ghost-htb (npm) Unknown 11 months ago 11 months ago
@dvargas135/gunpowder-ghost Malicious code in @dvargas135/gunpowder-ghost (npm) Unknown 11 months ago 11 months ago
gunpowder-ghost-curse Malicious code in gunpowder-ghost-curse (npm) Unknown 11 months ago 11 months ago
@asarioglo/npm-ghost-htb Malicious code in @asarioglo/npm-ghost-htb (npm) Unknown 11 months ago 11 months ago
availab-le-alb-um-zip-a-ghost-is-born-fgmfl-kscsps Malicious code in availab-le-alb-um-zip-a-ghost-is-born-fgmfl-kscsps (npm) Unknown 1 year ago 1 year ago
gboxghost Malicious code in gboxghost (npm) Unknown 1 year ago 1 year ago
ghostdrop Malicious code in ghostdrop (npm) Unknown 1 year ago 1 year ago
ghostlulz-dependency Malicious code in ghostlulz-dependency (npm) Unknown 1 year ago 1 year ago
ghosts3c Malicious code in ghosts3c (npm) Unknown 1 year ago 1 year ago
@tryghost/members-csv Ghost allows CSV Injection during member CSV export High Risk 8.8 2 years ago 1 year ago
ghost Ghost's improper authentication allows access to member information and actions Medium Risk 6.5 2 years ago 1 year ago