Vulnerabilities
Vulnerable Software
Ghost:  >> Ghost  >> 5.81.1  Security Vulnerabilities
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-08-20
Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.
CVSS Score
9.1
EPSS Score
0.004
Published
2024-06-16
Ghost before 5.82.0 allows CSV Injection during a member CSV export.
CVSS Score
8.8
EPSS Score
0.001
Published
2024-05-22


Contact Us

Shodan ® - All rights reserved