Known Vulnerabilities for products from Ghost
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Ghost".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-53567 | Not Provided | 2025-08-20 | 2026-04-01 | |
| CVE-2025-26909 | Not Provided | 2025-03-27 | 2026-04-01 | |
| CVE-2021-39192 | Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and... | 7.2 - HIGH | 2021-09-03 | 2021-09-10 |
| CVE-2021-29484 | Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted users... | 6.8 - MEDIUM | 2021-04-29 | 2021-09-14 |
| CVE-2020-24736 | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.5 - MEDIUM | 2023-04-11 | 2023-05-26 |
| CVE-2020-8134 | Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network o... | 8.1 - HIGH | 2020-03-20 | 2020-03-26 |
| CVE-2016-10983 | The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of export... | 6.5 - MEDIUM | 2019-09-17 | 2019-09-18 |
Known software with vulnerabilities from Ghost
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Ghost | Ghost | - |