-Infinity
0

Ghost GhostGhost: Cross-Site Scripting in Universal Import

Risk 35
Severity
5
First published (updated )

Ghost Ghost CLIGhost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header

Risk 29
Severity
6.3
First published (updated )

Ghost GhostGhost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

Risk 80
Severity
9.6
First published (updated )

Ghost GhostGhost: Mobiledoc image-size fetch SSRF

Risk 34
Severity
5.4
First published (updated )

Ghost GhostGhost: Member existence leak via magic link sign-in response

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Ghost GhostGhost: File Upload Content-Type Spoofing

Risk 34
Severity
5.4
First published (updated )

Ghost GhostGhost Content API filter bypass reveals private fields

Risk 27
Severity
5.3
First published (updated )

Ghost CMS flaw being actively exploited to compromise 700+ sites and serve malware to visitors through fake CAPTCHAs. Patch has been out since February

First published (updated )
Social
reddit

BleepingComputerGhost CMS SQL injection flaw exploited in large-scale ClickFix campaign

First published (updated )

npm/ghostGhost: Incomplete CSRF protections around OTC use

Risk 56
Severity
8.8
EPSS
0.02%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/ghostGhost Vulnerable to Remote Code Execution via Malicious Themes

Risk 47
Severity
9.8
EPSS
0.05%
First published (updated )

npm/ghostGhost has a SQL Injection in its Content API

Risk 69
Severity
9.4
EPSS
0.10%
First published (updated )

npm/ghostGhost vulnerable to XSS via malicious Portal preview links

Risk 56
Severity
8.8
EPSS
0.01%
First published (updated )

npm/ghostGhost has SQL Injection in Members Activity Feed

Risk 49
Severity
7.2
EPSS
0.10%
First published (updated )

npm/ghostGhost has SSRF via External Media Inliner

Risk 12
Severity
2.7
EPSS
0.07%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/ghostGhost has Staff Token permission bypass

Risk 43
Severity
8.1
EPSS
0.08%
First published (updated )

npm/ghostGhost has Staff 2FA bypass

Risk 43
Severity
8.1
EPSS
0.03%
First published (updated )

npm/ghostGhost 6.0.6 - SSRF via oEmbed Bookmark

Risk 27
Severity
6.5
EPSS
0.02%
First published (updated )

npm/@tryghost/portalGhost's improper authentication allows access to member information and actions

Risk 41
Severity
6.5
First published (updated )

Ghost GhostGhost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mecha…

Risk 66
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/@tryghost/members-csvGhost before 5.82.0 allows CSV Injection during a member CSV export.

Risk 81
Severity
8.8
First published (updated )

npm/ghostXSS

Risk 56
Severity
9
EPSS
0.04%
First published (updated )

npm/ghostXSS

Risk 28
Severity
6.1
EPSS
0.05%
First published (updated )

npm/ghostArbitrary file read via symlinks in Ghost

Risk 65
Severity
6.5
First published (updated )

npm/ghostPath Traversal

Risk 65
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/ghostGhost vulnerable to disclosure of private API fields

Risk 44
Severity
7.5
First published (updated )

Ghost Sqlite3 Node.jsBuffer Overflow, SQL Injection

Risk 32
Severity
5.5
First published (updated )

Ghost Sqlite3 Node.jsSQL Injection

Risk 86
Severity
9.8
First published (updated )

Ghost Ghost Node.jsGhost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is…

Risk 33
Severity
5.7
First published (updated )

Ghost Ghost Node.jsXSS

Risk 74
Severity
9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203