Ghost 版本 4.39.0 之前至 6.64.0 之前的版本存在信息泄露漏洞,该漏洞位于 Admin API 中,允许员工用户查看待处理的员工邀请中的秘密令牌。具有邀请查看权限的员工用户可接受更高特权角色的待处理邀请,从而提升自身权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104414 | 8.1 HIGH | Ghost from 2.5.0 before 6.64.0 Stored XSS via oEmbed Photo Responses |
| CVE-2026-104413 | 7.3 HIGH | Ghost 5.94.0 before 6.64.0 Stored XSS via Bookmark Card Images |
| CVE-2026-104411 | 7.3 HIGH | Ghost 6.22.1 before 6.64.0 Stored XSS via Local Storage File Uploads |
| CVE-2026-104418 | 7.2 HIGH | Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files |
| CVE-2026-104417 | 4.9 MEDIUM | Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting |
| CVE-2026-104412 | 4.3 MEDIUM | Ghost 0.5.0 before 6.64.0 Privilege Escalation via Staff Role Assignment |
| CVE-2026-104415 | 3.1 LOW | Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API |
No comments yet