ghost vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-9862Mediumghost: Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed BookmarkCVE-2024-43409Mediumghost: Ghost's improper authentication allows access to member information and actionsCVE-2024-23724Mediumghost: Ghost has possible Cross-site Scripting issueCVE-2024-23725Mediumghost: Cross-site Scripting in GhostCVE-2023-40028Mediumghost: Ghost vulnerable to arbitrary file read via symlinks in content importCVE-2023-32235Highghost: Path Traversal in GhostCVE-2023-31133Highghost: Ghost vulnerable to information disclosure of private API fieldsCVE-2022-41654Highghost: ghost vulnerable to unauthorized newsletter modification via improper access controlsGHSA-7V28-G2PQ-GGG8Mediumghost: Ghost vulnerable to remote code execution in locale setting changeCVE-2022-27139Criticalghost: Arbitrary file upload in GhostCVE-2022-28397Criticalghost: Arbitrary file upload in GhostGHSA-65P7-PJJ8-GGMRMediumghost: Member account takeoverGHSA-WFRJ-QQC2-83CMMediumghost: Remote command injection when using sendmail email transportCVE-2021-39192Mediumghost: Privilege escalation: all users can access Admin-level API keysCVE-2020-8134Mediumghost: Server-side request forgery in Ghost CMSCVE-2021-29484Mediumghost: DOM XSS in Theme Preview

Stop the waste.
Protect your environment with Kodem.