Ghost CMS 漏洞列表
共找到 2 个与 Ghost CMS 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2021-29484: Ghost CMS <=4.32 - Cross-Site Scripting POC
Ghost CMS 4.0.0 to 4.3.2 contains a DOM cross-site scripting vulnerability. An unused endpoint added during the development of 4.0.0 allows attackers to gain access by getting logged-in users to click a link containing malicious code. -
CVE-2023-32235: Ghost CMS < 5.42.1 - Path Traversal POC
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal. This occurs in frontend/web/middleware/static-theme.js.