Ghost 是一个基于 Node.js 的内容管理系统。从版本 4.0.0 至 6.67.0,在导入内容时,其中包含的 SVG 图片未经过任何清理(sanitization)处理即被直接存储。攻击者若能诱导管理员导入特制的文件,即可在站点域名下托管恶意脚本,可能导致员工用户的管理会话被劫持或系统被进一步渗透。该问题已在版本 6.67.0 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105642 | 8.8 HIGH | Ghost: Remote Code Execution via Bookmark Card Images |
| CVE-2026-105650 | 8.1 HIGH | Ghost: Stored XSS via oEmbed Photo Responses |
| CVE-2026-105675 | 7.5 HIGH | Ghost: Invite Token Disclosure in Ghost Admin API |
| CVE-2026-105643 | 7.3 HIGH | Ghost: Stored XSS via Embed Card Previews |
| CVE-2026-105651 | 7.3 HIGH | Ghost: Stored XSS via Bookmark Card Images |
| CVE-2026-105679 | 7.3 HIGH | Ghost: Stored XSS via File Uploads on Local Storage |
| CVE-2026-105649 | 7.3 HIGH | Ghost: Stored XSS via SVG Uploads Bypassing Sanitization |
| CVE-2026-105677 | 7.2 HIGH | Ghost: Remote Code Execution via Theme Translation Files |
| CVE-2026-105681 | 6.5 MEDIUM | Ghost: Authorization Bypass in Comments Feature |
| CVE-2026-105680 | 6.5 MEDIUM | Ghost: Authorization Issue Allowed Author Role to Delete any Post |
| CVE-2026-105646 | 4.9 MEDIUM | Ghost: Regular Expression Denial of Service in Content Import |
| CVE-2026-105645 | 4.9 MEDIUM | Ghost: Regular Expression Denial of Service in External Media Inliner |
| CVE-2026-105676 | 4.9 MEDIUM | Ghost: Path Traversal via Locale Setting |
| CVE-2026-105678 | 4.3 MEDIUM | Ghost: Editors Could Promote Staff Users to Their Own Role |
| CVE-2026-105647 | 4.0 MEDIUM | Ghost: Server-Side Request Forgery in Bookmark Fetching |
| CVE-2026-105648 | 4.0 MEDIUM | Ghost: Private IP Filtering Bypass via IPv6 Transition Addresses |
| CVE-2026-105683 | 3.8 LOW | Ghost: Path Traversal Vulnerability in Ghost ImageSize Service |
| CVE-2026-105652 | 3.1 LOW | Ghost: Password Hash Ordering Disclosure in Ghost Admin API |
| CVE-2026-105682 | 2.7 LOW | Ghost: Server-Side Request Forgery in Webhook Trigger |
No comments yet