Vendor
medium
threat
Arbitrary File Read in Ghost CMS via CVE-2023-40028
1 rule 1 TTP 1 CVEGhost CMS versions prior to 5.59.1 are vulnerable to an authenticated arbitrary file read, exploitable through malicious symbolic link uploads via the administrative API.
exploited
Ghost CMS
ghost-cms
arbitrary-file-read
web-application
cve-2023-40028
vulnerability
1r
1t
1c
high
advisory
Cross-Site Scripting Vulnerability in Ghost ActivityPub Client
1 TTP 1 CVEAn XSS vulnerability in the @tryghost/activitypub package (CVE-2026-53950) allows attackers to inject arbitrary JavaScript via malicious ActivityPub server posts.
@tryghost/activitypub
xss
web-vulnerability
activitypub
1t
1c
high
advisory
Ghost CMS 6.19.0 SQL Injection Vulnerability
2 rules 1 TTPA SQL injection vulnerability exists in Ghost CMS 6.19.0, and a public exploit (EDB-52555) is available, increasing the risk to unpatched systems.
Ghost CMS 6.19.0
sqli
webapps
ghostcms
2r
1t