Ghost是Ghost基金会开源的一款内容管理平台。 Ghost 6.0.9至6.21.1版本存在安全漏洞,该漏洞源于IP过滤绕过,可能导致攻击者利用映射到私有IPv4地址的IPv6地址绕过内部服务访问限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53943 | 9.6 CRITICAL | Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header |
| CVE-2026-53950 | 7.5 HIGH | @tryghost/activitypub: XSS in Ghost's ActivityPub client |
| CVE-2026-53948 | 5.4 MEDIUM | Ghost: File Upload Content-Type Spoofing |
| CVE-2026-53946 | 5.4 MEDIUM | Ghost: Mobiledoc image-size fetch SSRF |
| CVE-2026-53947 | 5.3 MEDIUM | Ghost: Member existence leak via magic link sign-in response |
| CVE-2026-53949 | 5.3 MEDIUM | Ghost Content API filter bypass reveals private fields |
| CVE-2026-53945 | 4.0 MEDIUM | Ghost: Server-side request forgery via DNS rebinding in external request handling |
No comments yet