CVE-2026-105649
- EPSS 0.3%
- Veröffentlicht 05.10.2026 19:05:37
- Zuletzt bearbeitet 06.10.2026 15:17:14
Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts ...
CVE-2026-105644
- EPSS 0.32%
- Veröffentlicht 05.10.2026 18:53:08
- Zuletzt bearbeitet 06.10.2026 15:17:13
Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in content imports were stored without sanitization. An attacker who convinced an Administrator to import a crafted file could host scripts on the site's domai...
CVE-2026-104417
- EPSS 0.37%
- Veröffentlicht 02.10.2026 11:37:59
- Zuletzt bearbeitet 02.10.2026 17:59:09
Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to read JSON files outside the active theme directory. Attackers can manipulate the locale setting to l...
CVE-2026-104416
- EPSS 0.31%
- Veröffentlicht 02.10.2026 11:37:59
- Zuletzt bearbeitet 06.10.2026 03:16:59
Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher...
CVE-2026-104415
- EPSS 0.21%
- Veröffentlicht 02.10.2026 11:37:58
- Zuletzt bearbeitet 02.10.2026 17:59:09
Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relative ordering of other staff users' password hashes. Authenticated staff users can query the Admin API...
CVE-2026-104414
- EPSS 0.28%
- Veröffentlicht 02.10.2026 11:37:57
- Zuletzt bearbeitet 02.10.2026 18:17:01
Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embedding ...
CVE-2026-104413
- EPSS 0.26%
- Veröffentlicht 02.10.2026 11:37:57
- Zuletzt bearbeitet 02.10.2026 17:59:09
Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to host arbitrary HTML by abusing bookmark card image fetching. Attackers can create bookmark cards that store non-i...
CVE-2026-104412
- EPSS 0.19%
- Veröffentlicht 02.10.2026 11:37:56
- Zuletzt bearbeitet 06.10.2026 03:16:59
Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to other staff despite lacking permission to do so. An authenticated Editor or Super Editor can ...
CVE-2026-104411
- EPSS 0.26%
- Veröffentlicht 02.10.2026 11:37:55
- Zuletzt bearbeitet 02.10.2026 18:17:00
Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served with extension-derived content types on the default local storage adapter. Attackers can upload scr...
CVE-2026-103292
- EPSS 0.23%
- Veröffentlicht 01.10.2026 10:42:25
- Zuletzt bearbeitet 01.10.2026 15:06:17
Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted by the {{ghost_head}} helper. An authenticated user with limited privileges can inject unescaped content that is rendered as s...