7.3
CVE-2026-105649
- EPSS 0.3%
- Veröffentlicht 05.10.2026 19:05:37
- Zuletzt bearbeitet 06.10.2026 15:17:14
- Erkennungen
Ghost: Stored XSS via SVG Uploads Bypassing Sanitization
Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.65.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerTryGhost
≫
Produkt
Ghost
Version
>= 4.22.0, < 6.65.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.209 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.3 | 2.1 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://github.com/TryGhost/Ghost/releases/tag/v6.65.0
https://github.com/TryGhost/Ghost/security/advisories/GHSA-8575-cr6v-7jh4
https://github.com/TryGhost/Ghost/issues/30919
https://github.com/TryGhost/Ghost/commit/80686226d23df56749f6b7ebb484850a8eba8072