References https://nvd.nist.gov/vuln/detail/cve-2023-32235 https://github.com/advisories/GHSA-wf7x-fh6w-34r6 https://www.invicti.com/web-application-vulnerabilities/ghost-cms-theme-path-traversal-cve-2023-32235 https://cve.imfht.com/poc_detail/f88a999e150852e78ce4b7c8405112224f9f584e https://www.juniper.net/us/en/threatlabs/ips-signatures/detail.HTTP:DIR:GHOSTCMS-STIC-THME-PT.html https://pentest-tools.com/vulnerabilities-exploits/ghost-cms-5421-path-traversal_2607 https://vulners.com/search/vendors/ghost/products/ghost
Related VulnerabilitiesPoCCVE-2026-3326: XStore Theme < 9.7.3 - SQL InjectionXStore Theme / SQL 注入漏洞(CVE-2026-3326)changedetection.io /static/%2e%2e/flask_app.py 目录遍历漏洞(CVE-2026-25527)Ghost CMS /assets/built 目录遍历漏洞(CVE-2023-32235)PoCCVE-2024-10763: WordPress Campress Theme <= 1.35 - Unauthenticated Local File InclusionPoCCVE-2024-32825: Simply Static - Information DisclosurePoCCVE-2025-11693: Export WP Page to Static HTML <= 4.3.4 - Cookie ExposurePoCCVE-2025-4524: WordPress Madara Theme < 2.2.2.1 - Local File InclusionGhost CMS /ghost/api/content/tags SQL 注入漏洞(CVE-2026-26980)PoCCVE-2025-2558: WordPress The Wound Theme <= 0.0.1 - Local File InclusionPoCCVE-2026-26980: Ghost CMS Content API - SQL InjectionGradio /static//windows/win.ini 文件读取漏洞 (CVE-2026-28414)Ghost CMS < 5.42.1存在sql注入漏洞(CVE-2026-26980)