Ghost 2.5.0 至 6.64.0(不含)版本中存在一个存储型跨站脚本(XSS)漏洞,攻击者可以通过 oEmbed 照片响应将不受信任的脚本注入到文章(post)内容中。攻击者可托管恶意的 oEmbed 照片响应,使得嵌入其 URL 后,在 Ghost 编辑器、已发布的网站以及新闻邮件中执行这些脚本,从而危及工作人员管理会话的安全。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104416 | 7.5 HIGH | Ghost 4.39.0 before 6.64.0 Invite Token Disclosure via Admin API |
| CVE-2026-104413 | 7.3 HIGH | Ghost 5.94.0 before 6.64.0 Stored XSS via Bookmark Card Images |
| CVE-2026-104411 | 7.3 HIGH | Ghost 6.22.1 before 6.64.0 Stored XSS via Local Storage File Uploads |
| CVE-2026-104418 | 7.2 HIGH | Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files |
| CVE-2026-104417 | 4.9 MEDIUM | Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting |
| CVE-2026-104412 | 4.3 MEDIUM | Ghost 0.5.0 before 6.64.0 Privilege Escalation via Staff Role Assignment |
| CVE-2026-104415 | 3.1 LOW | Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API |
No comments yet