Exposição de Ghost

Blogs, CMS
83
score de exposição
3.066
sites usam
0
em exploração
7
críticos
Análise Vexday

O Ghost acumula 31 CVEs catalogadas, das quais nenhuma consta no catálogo KEV da CISA, posicionando a tecnologia abaixo da média geral do catálogo em termos de exploração ativa confirmada. Ainda assim, o volume de 8 vulnerabilidades surgidas nos últimos 90 dias e a existência de 7 de severidade crítica indicam uma superfície de ataque em expansão que merece acompanhamento contínuo. O tipo de falha mais recorrente é CWE-918 (Server-Side Request Forgery), o que sugere fragilidades na forma como a aplicação realiza requisições externas — uma classe de vulnerabilidade frequentemente encadeada em ataques mais complexos. A CVE mais preocupante no momento é CVE-2026-26980, com pontuação EPSS de aproximadamente 0,70, sinalizando probabilidade relevante de exploração em curto prazo e justificando priorização imediata nas rotinas de patching.

CVEs

41 resultados
CVE-2026-26980CRITICALGhost has a SQL Injection in its Content APIEPSS 69.3%CVE-2023-40028MEDIUMArbitrary file read via symlinks in GhostEPSS 57.6%CVE-2023-31133HIGHGhost vulnerable to disclosure of private API fieldsEPSS 45.7%CVE-2022-41697MEDIUMA user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can leaEPSS 20.2%CVE-2022-41654CRITICALAn authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafEPSS 18.9%CVE-2021-29484MEDIUMDOM XSS in Theme PreviewEPSS 7.9%CVE-2020-8134Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise intEPSS 1.2%CVE-2022-47197CRITICALAn insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost EPSS 1.0%CVE-2021-39192MEDIUMPrivilege escalation: all users can access Admin-level API keysEPSS 1.0%CVE-2022-47194CRITICALAn insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost EPSS 0.8%CVE-2024-34559HIGHWordPress Ghost plugin <= 1.4.0 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.7%CVE-2022-47195CRITICALAn insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost EPSS 0.7%CVE-2022-47196CRITICALAn insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost EPSS 0.7%CVE-2026-22595HIGHGhost has Staff Token permission bypassEPSS 0.5%CVE-2025-9862MEDIUMGhost 6.0.6 - SSRF via oEmbed BookmarkEPSS 0.5%CVE-2026-22596MEDIUMGhost has SQL Injection in Members Activity FeedEPSS 0.4%CVE-2026-29053HIGHGhost Vulnerable to Remote Code Execution via Malicious ThemesEPSS 0.4%CVE-2026-22594HIGHGhost has Staff 2FA bypassEPSS 0.4%CVE-2024-43409MEDIUMGhost's improper authentication allows access to member information and actionsEPSS 0.3%CVE-2026-70592MEDIUMGhost: Database Backup Path TraversalEPSS 0.3%