ZeroHour

Vulnerabilities

48 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-26982
Ghostty is a cross-platform terminal emulator.

Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dropped text. These can be used to execute arbitrary commands in some shell environments. This attack requires an attacker to convince the user to copy and paste or drag and drop malicious text. The attack requires user interaction to be triggered, but the dangerous characters are invisible in most GUI environments so it isn't trivially detected, especially if the string contents are complex. Fixed in Ghostty v1.3.0.

NVD description · AI analysis pending
8.8<1%
  • ghostty ghostty
CVE-2026-29784
Ghost is a Node.js content management system.

Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to use OTCs in login sessions different from the requesting session. In some scenarios this might have made it easier for phishers to take over a Ghost site. This issue has been patched in version 6.19.3.

NVD description · AI analysis pending
8.8<1%
  • ghost ghost
CVE-2026-28785
+1 in the same advisory: …28680
Ghostfolio is an open source wealth management software.

Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them to read, modify, or delete sensitive financial data for all users in the database. This issue has been patched in version 2.244.0.

NVD description · AI analysis pending
9.3<1%
  • ghostfol ghostfolio
CVE-2026-29053
Ghost is a Node.js content management system.

Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.

NVD description · AI analysis pending
9.84%
  • ghost ghost
CVE-2026-26980
Unauthenticated SQL Injection in Ghost CMS Allows Arbitrary Database Reads

Ghost CMS versions 3.24.0 through 6.19.0 contain an unauthenticated SQL injection flaw (CWE-89) that lets a remote attacker trigger arbitrary reads against the site's database over the network, with no privileges or user interaction required. The attacker gains read access to database contents — high confidentiality impact per the CVSS vector (C:H/I:N/A:N), which can expose user, post, and session data. Any Ghost deployment running a release within the affected range is exposed, and the fix is in version 6.19.1. The flaw is not yet in the CISA KEV catalog and no public PoC is catalogued, but news reports indicate active in-the-wild exploitation: attackers have already hijacked more than 700 Ghost sites and used them to deliver ClickFix social-engineering attacks.

Do: Upgrade to Ghost 6.19.1 or later immediately if running any version from 3.24.0 through 6.19.0. Given the high EPSS (70.2% in 30 days) and confirmed mass exploitation, review logs for unauthenticated database-reading requests, rotate credentials and invalidate sessions in case sensitive data was read, and check site content and admin accounts for tampering consistent with the reported ClickFix hijacking campaign.

7.570%
  • Ghost 3.24.0 through 6.19.0 (fixed in 6.19.1)
masshundreds of thousands of internet-facing Ghost sites; 700+ already confirmed hijacked
CVE-2026-24778
Ghost is an open source content management system.

Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0.0 through 6.14.0, an attacker was able to craft a malicious link that, when accessed by an authenticated staff user or member, would execute JavaScript with the victim's permissions, potentially leading to account takeover. Ghost Portal versions 2.29.1 through 2.51.4 and 2.52.0 through 2.57.0 were vulnerable to this issue. Ghost automatically loads the latest patch of the members Portal component via CDN. For Ghost 5.x users, upgrading to v5.121.0 or later fixes the vulnerability. v5.121.0 loads Portal v2.51.5, which contains the patch. For Ghost 6.x users, upgrading to v6.15.0 or later fixes the vulnerability. v6.15.0 loads Portal v2.57.1, which contains the patch. For Ghost installations using a customized or self-hosted version of Portal, it will be necessary to manually rebuild from or update to the latest patch version.

NVD description · AI analysis pending
6.1<1%
  • ghost ghost
  • ghost portal
CVE-2026-22594
+3 in the same advisory: …22595 …22596 …22597
Ghost is a Node.js content management system.

Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA. This issue has been patched in versions 5.130.6 and 6.11.0.

NVD description · AI analysis pending
8.1
group max
1%
  • ghost ghost
CVE-2025-41108
+2 in the same advisory: …41109 …41110
The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to the robot from an external attack station

The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to the robot from an external attack station, impersonating the control station (tablet) and gaining unauthorised full control of the robot. The absence of encryption and authentication mechanisms in the communication protocol allows an attacker to capture legitimate traffic between the robot and the controller, replicate it, and send any valid command to the robot from any attacking computer or device. The communication protocol used in this interface is based on MAVLink, a widely documented protocol, which increases the likelihood of attack. There are two methods for connecting to the robot remotely: Wi-Fi and 4G/LTE.

NVD description · AI analysis pending
9.2
group max
<1%
  • ghostrobotics vision 60 firmware
CVE-2025-60834
+1 in the same advisory: …60833
A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input.

A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input.

NVD description · AI analysis pending
6.5<1% PoC
  • ghostxbh uzy-ssm-mall
CVE-2025-9862
Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost:

Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3.

NVD description · AI analysis pending
6.1<1% PoC
  • ghost ghost
CVE-2025-3559
+3 in the same advisory: …3558 …3561 …3560
A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical.

A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical. This vulnerability affects the function ForeProductListController of the file /mall/product/0/20. The manipulation of the argument orderBy leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.3
group max
<1% PoC
  • ghostxbh uzy-ssm-mall
CVE-2024-43409
Ghost is a Node.js content management system.

Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.

NVD description · AI analysis pending
6.5<1%
  • ghost ghost
CVE-2024-34451
Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different va

Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.

NVD description · AI analysis pending
9.1<1% PoC
  • ghost ghost
CVE-2024-34448
Ghost before 5.82.0 allows CSV Injection during a member CSV export.

Ghost before 5.82.0 allows CSV Injection during a member CSV export.

NVD description · AI analysis pending
8.8<1% PoC
  • ghost ghost
CVE-2024-23724
Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile picture that con

Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile picture that contains JavaScript code to interact with the API on localhost TCP port 3001. NOTE: The discoverer reports that "The vendor does not view this as a valid vector."

NVD description · AI analysis pending
9.03% PoC
  • ghost ghost
CVE-2023-52189
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jhayghost Ideal Interactive Map allows Stored XSS.This iss

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jhayghost Ideal Interactive Map allows Stored XSS.This issue affects Ideal Interactive Map: from n/a through 1.2.4.

NVD description · AI analysis pending
5.4<1%
  • jhayghost ideal interactive map
CVE-2024-23725
Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js.

Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries.

NVD description · AI analysis pending
6.1<1%
  • ghost ghost
CVE-2023-40028
Ghost is an open source content management system.

Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system. Site administrators can check for exploitation of this issue by looking for unknown symlinks within Ghost's `content/` folder. Version 5.59.1 contains a fix for this issue. All users are advised to upgrade. There are no known workarounds for this vulnerability.

NVD description · AI analysis pending
6.569%
  • ghost ghost
CVE-2023-30237
CyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe.

CyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe.

NVD description · AI analysis pending
7.8<1% PoC
  • cyberghostvpn cyberghost
CVE-2023-31133
Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid subscriptions to members.

Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid subscriptions to members. Prior to version 5.46.1, due to a lack of validation when filtering on the public API endpoints, it is possible to reveal private fields via a brute force attack. Ghost(Pro) has already been patched. Maintainers can find no evidence that the issue was exploited on Ghost(Pro) prior to the patch being added. Self-hosters are impacted if running Ghost a version below v5.46.1. v5.46.1 contains a fix for this issue. As a workaround, add a block for requests to `/ghost/api/content/*` where the `filter` query parameter contains `password` or `email`.

NVD description · AI analysis pending
7.546%
  • ghost ghost
CVE-2023-32235
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal.

Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal. This occurs in frontend/web/middleware/static-theme.js.

NVD description · AI analysis pending
7.539%
  • ghost ghost
CVE-2020-24736
Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script.

Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script.

NVD description · AI analysis pending
5.5<1% PoC
  • ghost sqlite3
CVE-2022-43441
A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1.

A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trigger this vulnerability.

NVD description · AI analysis pending
9.82% PoC
  • ghost sqlite3
CVE-2023-26510
Ghost 5.35.0 allows authorization bypass:

Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in which a contributor's draft can only be read by editors until published by an editor. NOTE: the vendor's position is that this behavior has no security impact.

NVD description · AI analysis pending
5.7<1%
  • ghost ghost
CVE-2022-47197
+3 in the same advisory: …47194 …47196 …47195
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `codeinjection_foot` for a post.

NVD description · AI analysis pending
5.41% PoC
  • ghost ghost
CVE-2022-41697
+1 in the same advisory: …41654
A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4.

A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigger this vulnerability.

NVD description · AI analysis pending
5.3
group max
20% PoC
  • ghost ghost
CVE-2022-21227
The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter.

The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.

NVD description · AI analysis pending
7.52%
  • ghost sqlite3
CVE-2022-27139
+1 in the same advisory: …28397
An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file.

An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. NOTE: Vendor states that as outlined in Ghost's security documentation, upload of SVGs is only possible by trusted authenticated users. The uploading of SVG files to Ghost does not represent a remote code execution vulnerability. SVGs are not executable on the server, and may only execute javascript in a client's browser - this is expected and intentional functionality

NVD description · AI analysis pending
9.84% PoC
  • ghost ghost
CVE-2021-39192
Ghost is a Node.js content management system.

Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint, leading to a privilege escalation vulnerability. This issue is patched in Ghost version 4.10.0. As a workaround, disable all non-Administrator accounts to prevent API access. It is highly recommended to regenerate all API keys after patching or applying the workaround.

NVD description · AI analysis pending
7.21%
  • ghost ghost
CVE-2021-29484
Ghost is a Node.js CMS.

Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted users gaining access to Ghost Admin. Attackers can gain access by getting logged in users to click a link containing malicious code. Users do not need to enter credentials and may not know they've visited a malicious site. Ghost(Pro) has already been patched. We can find no evidence that the issue was exploited on Ghost(Pro) prior to the patch being added. Self-hosters are impacted if running Ghost a version between 4.0.0 and 4.3.2. Immediate action should be taken to secure your site. The issue has been fixed in 4.3.3, all 4.x sites should upgrade as soon as possible. As the endpoint is unused, the patch simply removes it. As a workaround blocking access to /ghost/preview can also mitigate the issue.

NVD description · AI analysis pending
6.88% PoC
  • ghost ghost
CVE-2020-8134
Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal

Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems.

NVD description · AI analysis pending
8.11% PoC
  • ghost ghost
CVE-2016-10983
The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.

The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.

NVD description · AI analysis pending
6.52% PoC
  • ghost ghost
CVE-2018-10646
CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "CG6Service" service.

CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "CG6Service" service. This service establishes a NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "ConnectToVpnServer" method accepts a "connectionParams" argument that provides attacker control of the OpenVPN command line. An attacker can specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM user.

NVD description · AI analysis pending
7.8<1%
  • cyberghostvpn cyberghost