Vulnerabilidades en TryGhost
33 resultadosAnálisis Vexday
TryGhost acumula 23 vulnerabilidades na base, sendo 9 publicadas nos últimos 90 dias, indicando ritmo recente de descobertas; a fraqueza dominante é exposição de informações (CWE-200), com apenas 2 críticas e nenhuma sob exploração ativa confirmada no KEV. O perfil sugere risco moderado, sem pressão imediata de ataques, mas com necessidade de monitoramento continuado das atualizações recentes.
CVE-2026-53947MEDIUMGhost: Member existence leak via magic link sign-in responseEPSS 0.2%CVE-2026-53950HIGH@tryghost/activitypub: XSS in Ghost's ActivityPub clientEPSS 0.2%CVE-2026-53944MEDIUMGhost: Private IP filtering bypass to make server-side requests to internal servicesEPSS 0.2%CVE-2026-70590MEDIUMGhost: Blind Password Hash Disclosure in Ghost Admin APIEPSS 0.2%CVE-2026-70596MEDIUMGhost: Cross-Site Scripting in Feature Image CaptionsEPSS 0.2%CVE-2026-70595MEDIUMGhost: Server-Side Request Forgery Mitigation IssueEPSS 0.2%CVE-2026-25552MEDIUMGhost CLI < 1.30.1 IP Spoofing via X-Forwarded-For HeaderEPSS 0.2%CVE-2026-70589MEDIUMGhost: Archived Offers can be RedeemedEPSS 0.2%CVE-2026-70594MEDIUMGhost: Session Fixation in Ghost AdminEPSS 0.2%CVE-2026-29784HIGHGhost: Incomplete CSRF protections around OTC useEPSS 0.2%CVE-2026-53945MEDIUMGhost: Server-side request forgery via DNS rebinding in external request handlingEPSS 0.1%CVE-2026-53948MEDIUMGhost: File Upload Content-Type SpoofingEPSS 0.1%CVE-2026-53946MEDIUMGhost: Mobiledoc image-size fetch SSRFEPSS 0.1%