Filter
-Infinity
0

npm/@tryghost/portalGhost's improper authentication allows access to member information and actions

First published (updated )

npm/ghostXSS

EPSS
0.04%
First published (updated )

npm/ghostXSS

EPSS
0.05%
First published (updated )

npm/ghostArbitrary file read via symlinks in Ghost

First published (updated )

npm/ghostPath Traversal

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

npm/ghostGhost vulnerable to disclosure of private API fields

7.5
First published (updated )

SQLiteBuffer Overflow, SQL Injection

First published (updated )

SQLiteSQL Injection

First published (updated )

Ghost Ghost Node.jsGhost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is…

First published (updated )

Ghost Ghost Node.jsXSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Ghost Ghost Node.jsXSS

First published (updated )

Ghost Ghost Node.jsXSS

First published (updated )

Ghost Ghost Node.jsXSS

First published (updated )

GhostAn authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost …

First published (updated )

Ghost Ghost Node.jsA user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. …

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

SQLiteDenial of Service (DoS)

7.5
First published (updated )

npm/ghostMalicious File Upload

First published (updated )

Ghost Ghost Node.jsMalicious File Upload

First published (updated )

Ghost Ghost Node.jsPrivilege escalation: all users can access Admin-level API keys

7.2
First published (updated )

Ghost Ghost Node.jsDOM XSS in Theme Preview

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Ghost Ghost Node.jsSSRF

8.1
First published (updated )

Ghost Foundation GhostThe ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport…

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203