Vulnerabilities > Ghost > Ghost > 0.5.9

DATE CVE VULNERABILITY TITLE RISK
2024-01-21 CVE-2024-23725 Cross-site Scripting vulnerability in Ghost
Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js.
network
low complexity
ghost CWE-79
6.1
2023-08-15 CVE-2023-40028 Link Following vulnerability in Ghost
Ghost is an open source content management system.
network
low complexity
ghost CWE-59
6.5
2023-05-08 CVE-2023-31133 Unspecified vulnerability in Ghost
Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid subscriptions to members.
network
low complexity
ghost
7.5
2023-05-05 CVE-2023-32235 Path Traversal vulnerability in Ghost
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal.
network
low complexity
ghost CWE-22
7.5
2020-03-20 CVE-2020-8134 Server-Side Request Forgery (SSRF) vulnerability in Ghost
Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems.
network
low complexity
ghost CWE-918
5.5