Ghost 是一个基于 Node.js 的内容管理系统。从版本 6.22.1 到 6.64.0,Ghost 限制了用于服务上传文件的 Content-Type,以防止浏览器执行这些文件。然而,在使用默认本地存储适配器的网站上,这一限制并未生效,因此由任何工作人员用户上传的文件都会根据其文件扩展名确定 Content-Type 来提供服务。这可能导致攻击者在该网站域下托管脚本,从而可能引发其他工作人员管理员会话的 compromised(被攻破或劫持)。该问题已在版本 6.64.0 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105642 | 8.8 HIGH | Ghost: Remote Code Execution via Bookmark Card Images |
| CVE-2026-105650 | 8.1 HIGH | Ghost: Stored XSS via oEmbed Photo Responses |
| CVE-2026-105675 | 7.5 HIGH | Ghost: Invite Token Disclosure in Ghost Admin API |
| CVE-2026-105643 | 7.3 HIGH | Ghost: Stored XSS via Embed Card Previews |
| CVE-2026-105651 | 7.3 HIGH | Ghost: Stored XSS via Bookmark Card Images |
| CVE-2026-105649 | 7.3 HIGH | Ghost: Stored XSS via SVG Uploads Bypassing Sanitization |
| CVE-2026-105677 | 7.2 HIGH | Ghost: Remote Code Execution via Theme Translation Files |
| CVE-2026-105644 | 6.8 MEDIUM | Ghost: Stored XSS via SVG Files in Content Imports |
| CVE-2026-105681 | 6.5 MEDIUM | Ghost: Authorization Bypass in Comments Feature |
| CVE-2026-105680 | 6.5 MEDIUM | Ghost: Authorization Issue Allowed Author Role to Delete any Post |
| CVE-2026-105646 | 4.9 MEDIUM | Ghost: Regular Expression Denial of Service in Content Import |
| CVE-2026-105676 | 4.9 MEDIUM | Ghost: Path Traversal via Locale Setting |
| CVE-2026-105645 | 4.9 MEDIUM | Ghost: Regular Expression Denial of Service in External Media Inliner |
| CVE-2026-105678 | 4.3 MEDIUM | Ghost: Editors Could Promote Staff Users to Their Own Role |
| CVE-2026-105647 | 4.0 MEDIUM | Ghost: Server-Side Request Forgery in Bookmark Fetching |
| CVE-2026-105648 | 4.0 MEDIUM | Ghost: Private IP Filtering Bypass via IPv6 Transition Addresses |
| CVE-2026-105683 | 3.8 LOW | Ghost: Path Traversal Vulnerability in Ghost ImageSize Service |
| CVE-2026-105652 | 3.1 LOW | Ghost: Password Hash Ordering Disclosure in Ghost Admin API |
| CVE-2026-105682 | 2.7 LOW | Ghost: Server-Side Request Forgery in Webhook Trigger |
No comments yet