Security Advisories for ghost in npm
High
4 months ago
Ghost vulnerable to XSS via malicious Portal preview links
npm
ghost, @tryghost/portal
Moderate
9 months ago
Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark
npm
ghost
Moderate
almost 2 years ago
Ghost's improper authentication allows access to member information and actions
npm
@tryghost/portal, ghost
Moderate
almost 3 years ago
Ghost vulnerable to arbitrary file read via symlinks in content import
npm
ghost
High
over 3 years ago
ghost vulnerable to unauthorized newsletter modification via improper access controls
npm
ghost
Moderate
almost 4 years ago
Ghost vulnerable to remote code execution in locale setting change
npm
ghost
Moderate
almost 5 years ago
Privilege escalation: all users can access Admin-level API keys
npm
ghost