ghost vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-53943Criticalghost: Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview headerCVE-2026-29784Highghost: Ghost has incomplete CSRF protections around OTC useCVE-2026-29053Highghost: Ghost Vulnerable to Remote Code Execution via Malicious ThemesCVE-2026-26980Criticalghost: Ghost has a SQL injection in Content APICVE-2026-24778Highghost: Ghost vulnerable to XSS via malicious Portal preview linksCVE-2026-22596Mediumghost: Ghost has SQL Injection in Members Activity FeedCVE-2026-22597Mediumghost: Ghost has SSRF via External Media InlinerCVE-2026-22595Highghost: Ghost has Staff Token permission bypassCVE-2026-22594Highghost: Ghost has Staff 2FA bypassCVE-2025-9862Mediumghost: Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed BookmarkCVE-2024-43409Mediumghost: Ghost's improper authentication allows access to member information and actionsCVE-2024-23724Mediumghost: Ghost has possible Cross-site Scripting issueCVE-2024-23725Mediumghost: Cross-site Scripting in GhostCVE-2023-40028Mediumghost: Ghost vulnerable to arbitrary file read via symlinks in content importCVE-2023-32235Highghost: Path Traversal in GhostCVE-2023-31133Highghost: Ghost vulnerable to information disclosure of private API fieldsCVE-2022-41654Highghost: ghost vulnerable to unauthorized newsletter modification via improper access controlsGHSA-7V28-G2PQ-GGG8Mediumghost: Ghost vulnerable to remote code execution in locale setting changeCVE-2022-27139Criticalghost: Arbitrary file upload in GhostCVE-2022-28397Criticalghost: Arbitrary file upload in GhostGHSA-65P7-PJJ8-GGMRMediumghost: Member account takeoverGHSA-WFRJ-QQC2-83CMMediumghost: Remote command injection when using sendmail email transportCVE-2021-39192Mediumghost: Privilege escalation: all users can access Admin-level API keysCVE-2020-8134Mediumghost: Server-side request forgery in Ghost CMSCVE-2021-29484Mediumghost: DOM XSS in Theme Preview

Stop the waste.
Protect your environment with Kodem.