Vulnerabilities > Ghost > Ghost > 5.12.4

DATE CVE VULNERABILITY TITLE RISK
2024-08-20 CVE-2024-43409 Improper Authentication vulnerability in Ghost
Ghost is a Node.js content management system.
network
low complexity
ghost CWE-287
6.5
2024-02-11 CVE-2024-23724 Cross-site Scripting vulnerability in Ghost
Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile picture that contains JavaScript code to interact with the API on localhost TCP port 3001.
network
low complexity
ghost CWE-79
critical
9.0
2024-01-21 CVE-2024-23725 Cross-site Scripting vulnerability in Ghost
Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js.
network
low complexity
ghost CWE-79
6.1
2023-08-15 CVE-2023-40028 Link Following vulnerability in Ghost
Ghost is an open source content management system.
network
low complexity
ghost CWE-59
6.5
2023-05-08 CVE-2023-31133 Unspecified vulnerability in Ghost
Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid subscriptions to members.
network
low complexity
ghost
7.5
2023-05-05 CVE-2023-32235 Path Traversal vulnerability in Ghost
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal.
network
low complexity
ghost CWE-22
7.5
2022-12-22 CVE-2022-41654 Unspecified vulnerability in Ghost
An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4.
network
low complexity
ghost
4.3