Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ghost MEDIUM 5.7
CVE-2023-26510

Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in …

Mitigation only
Fix from $1,600 2023-03-05
Ghost MEDIUM 5.4
CVE-2022-47195

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non…

No fix yet
Fix from $1,600 2023-01-19
Ghost MEDIUM 5.4
CVE-2022-47196

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non…

No fix yet
Fix from $1,600 2023-01-19
Ghost MEDIUM 5.4
CVE-2022-47197

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non…

No fix yet
Fix from $1,600 2023-01-19
Ghost MEDIUM 5.4
CVE-2022-47194

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non…

No fix yet
Fix from $1,600 2023-01-19
Ghost MEDIUM 5.3
CVE-2022-41697EPSS 20%

A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a di…

No fix yet
Fix from $1,600 2022-12-22
Ghost CRITICAL 9.8
CVE-2022-28397

An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. …

Mitigation only
Fix from $2,300 2022-04-12
Ghost CRITICAL 9.8
CVE-2022-27139

An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. …

No fix yet
Fix from $2,300 2022-04-12