CVE-2023-32235
- EPSS 39.08%
- Veröffentlicht 05.05.2023 05:15:09
- Zuletzt bearbeitet 29.01.2025 17:15:26
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal. This occurs in frontend/web/middleware/static-theme.js.
CVE-2023-26510
- EPSS 0.63%
- Veröffentlicht 05.03.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:51:38
Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in which a contributor's draft can only be read by editors until published by an editor. NOTE: the vendo...
CVE-2022-47197
- EPSS 1.02%
- Veröffentlicht 19.01.2023 18:15:14
- Zuletzt bearbeitet 04.11.2025 20:16:14
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to adm...
CVE-2022-47196
- EPSS 0.68%
- Veröffentlicht 19.01.2023 18:15:14
- Zuletzt bearbeitet 04.11.2025 20:16:14
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to adm...
CVE-2022-47195
- EPSS 0.68%
- Veröffentlicht 19.01.2023 18:15:14
- Zuletzt bearbeitet 04.11.2025 20:16:14
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to adm...
CVE-2022-47194
- EPSS 0.82%
- Veröffentlicht 19.01.2023 18:15:13
- Zuletzt bearbeitet 04.11.2025 20:16:13
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to adm...
CVE-2022-41697
- EPSS 20.2%
- Veröffentlicht 22.12.2022 10:15:10
- Zuletzt bearbeitet 21.11.2024 07:23:40
A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigger this vul...
CVE-2022-41654
- EPSS 18.91%
- Veröffentlicht 22.12.2022 10:15:10
- Zuletzt bearbeitet 21.11.2024 07:23:34
An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulner...
CVE-2022-28397
- EPSS 3.25%
- Veröffentlicht 12.04.2022 17:15:10
- Zuletzt bearbeitet 09.07.2026 01:17:25
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and pub...
CVE-2022-27139
- EPSS 3.79%
- Veröffentlicht 12.04.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:55:13
An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. NOTE: Vendor states that as outlined in Ghost's security documentation, upload of SVGs is only possib...