Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ghost HIGH 8.8
CVE-2026-29784

Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to …

Fix: 6.19.3+
Fix from $1,950 2026-03-07
Ghost CRITICAL 9.8
CVE-2026-29053

Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the s…

Fix: 6.19.1+
Fix from $2,300 2026-03-05
Ghost HIGH 7.5
CVE-2026-26980EPSS 69%

Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the data…

Fix: 6.19.1+
Fix from $1,950 2026-02-20
Ghost MEDIUM 6.1
CVE-2026-24778

Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0.0 through 6.14.0, an attacker was able to craft a…

Fix: 2.51.5 / 2.57.1+
Fix from $1,600 2026-01-27
Ghost HIGH 8.1
CVE-2026-22594

Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism …

Fix: 5.130.6 / 6.11.0+
Fix from $1,950 2026-01-10
Ghost HIGH 8.1
CVE-2026-22595

Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of St…

Fix: 5.130.6 / 6.11.0+
Fix from $1,950 2026-01-10
Ghost HIGH 7.2
CVE-2026-22596

Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's /ghost/api/admi…

Fix: 5.130.6 / 6.11.0+
Fix from $1,950 2026-01-10
Ghost MEDIUM 6.5
CVE-2025-9862

Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 throug…

Fix: after 6.0.8
Fix from $1,600 2025-09-17
Ghost MEDIUM 6.5
CVE-2024-43409

Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform me…

Fix: 5.89.5+
Fix from $1,600 2024-08-20
Ghost CRITICAL 9.1
CVE-2024-34451

Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with d…

Fix: after 5.85.1
Fix from $2,300 2024-06-16
Ghost HIGH 8.8
CVE-2024-34448

Ghost before 5.82.0 allows CSV Injection during a member CSV export.

Fix: 5.82.0+
Fix from $1,950 2024-05-22
Ghost CRITICAL 9.0
CVE-2024-23724

Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile pictu…

Fix: after 5.76.0
Fix from $2,300 2024-02-11
Ghost MEDIUM 6.1
CVE-2024-23725

Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries.

Fix: 5.76.0+
Fix from $1,600 2024-01-21
Ghost MEDIUM 6.5
CVE-2023-40028EPSS 68%

Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload…

Fix: 5.59.1+
Fix from $1,600 2023-08-15
Ghost HIGH 7.5
CVE-2023-31133EPSS 46%

Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid subscriptions to members. Pri…

Fix: 5.46.1+
Fix from $1,950 2023-05-08
Ghost HIGH 7.5
CVE-2023-32235EPSS 39%

Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traver…

Fix: 5.42.1+
Fix from $1,950 2023-05-05
Sqlite3 MEDIUM 5.5
CVE-2020-24736

Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script.

Patch available
Fix from $1,600 2023-04-11
Sqlite3 CRITICAL 9.8
CVE-2022-43441

A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript …

Fix: 5.1.5+
Fix from $2,300 2023-03-16
Ghost MEDIUM 5.7
CVE-2023-26510

Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in …

Mitigation only
Fix from $1,600 2023-03-05
Ghost MEDIUM 5.4
CVE-2022-47195

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non…

No fix yet
Fix from $1,600 2023-01-19
Ghost MEDIUM 5.4
CVE-2022-47196

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non…

No fix yet
Fix from $1,600 2023-01-19
Ghost MEDIUM 5.4
CVE-2022-47197

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non…

No fix yet
Fix from $1,600 2023-01-19
Ghost MEDIUM 5.4
CVE-2022-47194

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non…

No fix yet
Fix from $1,600 2023-01-19
Ghost MEDIUM 5.3
CVE-2022-41697EPSS 20%

A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a di…

No fix yet
Fix from $1,600 2022-12-22
Sqlite3 HIGH 7.5
CVE-2022-21227

The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed…

Fix: 5.0.3+
Fix from $1,950 2022-05-01
Ghost CRITICAL 9.8
CVE-2022-28397

An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. …

Mitigation only
Fix from $2,300 2022-04-12
Ghost CRITICAL 9.8
CVE-2022-27139

An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. …

No fix yet
Fix from $2,300 2022-04-12
Ghost HIGH 7.2
CVE-2021-39192

Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authen…

Fix: 4.10.0+
Fix from $1,950 2021-09-03
Ghost MEDIUM 6.8
CVE-2021-29484EPSS 8%

Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted users gaining access to Ghost…

Fix: 4.3.3+
Fix from $1,600 2021-04-29
Ghost HIGH 8.1
CVE-2020-8134

Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact wit…

Fix: 3.10.0+
Fix from $1,950 2020-03-20