Vulnerabilidades en TryGhost

33 resultados
Análisis Vexday

TryGhost acumula 23 vulnerabilidades na base, sendo 9 publicadas nos últimos 90 dias, indicando ritmo recente de descobertas; a fraqueza dominante é exposição de informações (CWE-200), com apenas 2 críticas e nenhuma sob exploração ativa confirmada no KEV. O perfil sugere risco moderado, sem pressão imediata de ataques, mas com necessidade de monitoramento continuado das atualizações recentes.

CVE-2026-26980CRITICALGhost has a SQL Injection in its Content APIEPSS 69.3%CVE-2023-40028MEDIUMArbitrary file read via symlinks in GhostEPSS 57.6%CVE-2023-31133HIGHGhost vulnerable to disclosure of private API fieldsEPSS 45.7%CVE-2021-29484MEDIUMDOM XSS in Theme PreviewEPSS 7.9%CVE-2021-32817MEDIUMFile disclosure in express-hbsEPSS 1.3%CVE-2026-22594HIGHGhost has Staff 2FA bypassEPSS 1.1%CVE-2021-39192MEDIUMPrivilege escalation: all users can access Admin-level API keysEPSS 1.0%CVE-2026-29053HIGHGhost Vulnerable to Remote Code Execution via Malicious ThemesEPSS 1.0%CVE-2026-22595HIGHGhost has Staff Token permission bypassEPSS 0.5%CVE-2026-22596MEDIUMGhost has SQL Injection in Members Activity FeedEPSS 0.4%CVE-2024-43409MEDIUMGhost's improper authentication allows access to member information and actionsEPSS 0.3%CVE-2026-70592MEDIUMGhost: Database Backup Path TraversalEPSS 0.3%CVE-2026-70593MEDIUMGhost: Theme Upload Path TraversalEPSS 0.3%CVE-2026-53943CRITICALGhost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview headerEPSS 0.3%CVE-2026-22597MEDIUMGhost has SSRF via External Media InlinerEPSS 0.3%CVE-2026-70588MEDIUMGhost: Cross-Site Scripting in Universal ImportEPSS 0.3%CVE-2026-59817MEDIUMGhost: Paid gift memberships obtainable at minimal cost via the donations featureEPSS 0.3%CVE-2026-24778HIGHGhost vulnerable to XSS via malicious Portal preview linksEPSS 0.3%CVE-2026-70591MEDIUMGhost: Server-Side Request Forgery in Image FetchingEPSS 0.2%CVE-2026-53949MEDIUMGhost Content API filter bypass reveals private fieldsEPSS 0.2%