Ghost

Ghost

64 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.02%
  • Veröffentlicht 03.09.2021 15:15:09
  • Zuletzt bearbeitet 21.11.2024 06:18:50

Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint...

Exploit
  • EPSS 7.94%
  • Veröffentlicht 29.04.2021 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:01:14

Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted users gaining access to Ghost Admin. Attackers can gain access by getting logged in users to click a link containing malicious cod...

Exploit
  • EPSS 1.22%
  • Veröffentlicht 20.03.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:21

Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems.

Exploit
  • EPSS 1.52%
  • Veröffentlicht 17.09.2019 15:15:12
  • Zuletzt bearbeitet 21.11.2024 02:45:13

The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.