Security Advisories for ghost in npm
Moderate
12 days ago
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
npm
ghost
Moderate
12 days ago
Ghost: Server-side request forgery via DNS rebinding in external request handling
npm
ghost
Moderate
12 days ago
Ghost: Private IP filtering bypass to make server-side requests to internal services
npm
ghost
Critical
about 2 months ago
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
npm
ghost
High
7 months ago
Ghost vulnerable to XSS via malicious Portal preview links
npm
@tryghost/portal, ghost
Moderate
11 months ago
Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark
npm
ghost
Moderate
almost 2 years ago
Ghost's improper authentication allows access to member information and actions
npm
@tryghost/portal, ghost
Moderate
about 3 years ago
Ghost vulnerable to arbitrary file read via symlinks in content import
npm
ghost
High
over 3 years ago
ghost vulnerable to unauthorized newsletter modification via improper access controls
npm
ghost
Moderate
about 4 years ago
Ghost vulnerable to remote code execution in locale setting change
npm
ghost
Moderate
about 5 years ago
Privilege escalation: all users can access Admin-level API keys
npm
ghost