Vulnerabilities > Ghost

DATE CVE VULNERABILITY TITLE RISK
2020-03-20 CVE-2020-8134 Server-Side Request Forgery (SSRF) vulnerability in Ghost
Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems.
network
low complexity
ghost CWE-918
8.1
2019-09-17 CVE-2016-10983 Improper Authentication vulnerability in Ghost
The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.
network
low complexity
ghost CWE-287
6.5