CVE Tools

Ghost-foundation

4 CVEs tracked since 2023. Since Jan 2023, none of them reached CISA KEV.

Ghost-foundation CVEs per month

Jan 2023 to Jan 2023. Point at a month, or focus the strip and use the arrow keys.
Ghost-foundation CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-0140

Products

The products that kept showing up in Ghost-foundation's monthly top three, with their CVEs summed over those months.

  1. Ghost41 month

Latest CVEs

The 11 most recently published vulnerabilities affecting Ghost-foundation.

  1. CVE-2026-72596Ghost Foundation Ghost - Broken Access Control8.1
  2. CVE-2026-26980Ghost has a SQL Injection in its Content API9.4
  3. CVE-2024-34559WordPress Ghost plugin <= 1.4.0 - Sensitive Data Exposure via Log File vulnerability7.5
  4. CVE-2024-23724Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile picture that contains JavaScript code to interact wit...9.0
  5. CVE-2022-43441A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An at...8.1
  6. CVE-2022-47197An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascr...5.4
  7. CVE-2022-47195An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascr...5.4
  8. CVE-2022-47196An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascr...5.4
  9. CVE-2022-47194An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascr...5.4
  10. CVE-2022-41654An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An att...4.3
  11. CVE-2022-41697A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker c...5.3

The record

Peak rank
#133 in Jan 2023
Busiest month shown
Jan 2023, 4 CVEs
Months with a KEV entry
0 since Jan 2023
Monthly snapshots
1 since 2023
Ghost-foundation's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store