ghost
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 42 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 17, 2019 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Ghost: Cross-Site Scripting in Universal Import
Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
Ghost: Mobiledoc image-size fetch SSRF
Ghost: Member existence leak via magic link sign-in response
Ghost: File Upload Content-Type Spoofing
Ghost Content API filter bypass reveals private fields
Ghost CMS flaw being actively exploited to compromise 700+ sites and serve malware to visitors through fake CAPTCHAs. Patch has been out since February
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
Ghost: Incomplete CSRF protections around OTC use
Monitor ghost in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.