Ghost 在 5.94.0 版本之前至 6.64.0 版本之间存在一个存储型跨站脚本(XSS)漏洞。该漏洞允许包括 Contributors 在内的员工用户,通过滥用书签卡片图片获取功能,上传任意 HTML 内容。攻击者可创建书签卡片,将外部网站上的非图片文件存储为图标或缩略图,从而窃取其他员工用户的管理会话,导致会话被劫持。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104414 | 8.1 HIGH | Ghost from 2.5.0 before 6.64.0 Stored XSS via oEmbed Photo Responses |
| CVE-2026-104416 | 7.5 HIGH | Ghost 4.39.0 before 6.64.0 Invite Token Disclosure via Admin API |
| CVE-2026-104411 | 7.3 HIGH | Ghost 6.22.1 before 6.64.0 Stored XSS via Local Storage File Uploads |
| CVE-2026-104418 | 7.2 HIGH | Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files |
| CVE-2026-104417 | 4.9 MEDIUM | Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting |
| CVE-2026-104412 | 4.3 MEDIUM | Ghost 0.5.0 before 6.64.0 Privilege Escalation via Staff Role Assignment |
| CVE-2026-104415 | 3.1 LOW | Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API |
No comments yet