Ghost是Ghost开源的一个托管服务。 Ghost 5.121.0版本至5.130.5版本和6.0.0版本至6.10.3版本存在安全漏洞,该漏洞源于Ghost处理工作人员令牌身份验证的方式存在缺陷,可能导致某些仅限通过工作人员会话身份验证访问的端点被不当访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-22594 | 8.1 HIGH | Ghost has Staff 2FA bypass |
| CVE-2026-22596 | 6.7 MEDIUM | Ghost has SQL Injection in Members Activity Feed |
| CVE-2026-22597 | Ghost has SSRF via External Media Inliner |
No comments yet