Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
367 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.8) | — | — | GhostscriptAI | 6/10/2026 | 6/10/2026 | A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at… | |
| Aplazada | Baja (3.8) | 0.31% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue may have allowed staff users to access local files outside the intended data storage directories on the server. This issue is fixed in version 6.27.0. | |
| Aplazada | Baja (2.7) | 0.24% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an SSRF vulnerability in the webhooks feature allowed staff users to probe internal hosts from the Ghost server. This issue is fixed in version 6.27.0. | |
| Aplazada | Media (6.5) | 0.26% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 5.9.0 until 6.44.1, an input validation issue allowed members to access comments they were not authorized to access. This issue is fixed in version 6.44.1. | |
| Aplazada | Media (6.5) | 0.27% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 5.81.0 until 6.60.0, staff with the Author role could delete posts and pages that they did not author. This issue is fixed in version 6.60.0. | |
| Aplazada | Alta (7.3) | 0.24% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from executing them. On sites using the default local storage adapter, this restriction was not applied, so files uploaded by any staff user were served with a… | |
| Aplazada | Media (4.3) | 0.20% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role. This issue is fixed in version 6.64.0. | |
| Aplazada | Alta (7.2) | 0.52% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This issue is fixed in version 6.64.0. | |
| Aplazada | Media (4.9) | 0.40% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to read JSON files outside of the active theme's directory, potentially exposing server configuration secrets. This issue is fixed in version 6.64.0. | |
| Aplazada | Alta (7.5) | 0.39% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret token of pending invites, including invites for roles with higher privileges than their own. This could allow a staff user to escalate their privileges by accepting… | |
| Aplazada | Baja (3.1) | 0.26% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 0.7.2 until 6.64.0, any staff-level user was able to determine the relative ordering of other staff users' hashed passwords. This does not directly disclose password hashes, and does not provide a practical path to recovering a password. This issue is fixed in version… | |
| Aplazada | Alta (7.3) | 0.30% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from an external website as bookmark icons or thumbnails. This allowed any staff user, including Contributors, to host arbitrary HTML on the site's domain, possibly resulting… | |
| Aplazada | Alta (8.1) | 0.33% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting in compromise of a… | |
| Aplazada | Alta (7.3) | 0.30% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff… | |
| Aplazada | Media (4) | 0.30% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 6.0.9 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network on some network configurations. A successful attack would not… | |
| Aplazada | Media (4) | 0.23% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data… | |
| Aplazada | Media (4.9) | 0.33% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, a crafted content import file could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0. | |
| Aplazada | Media (4.9) | 0.33% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 5.37.0 until 6.67.0, a crafted request to the external media inliner could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0. | |
| Aplazada | Media (6.8) | 0.32% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in content imports were stored without sanitization. An attacker who convinced an Administrator to import a crafted file could host scripts on the site's domain, possibly resulting in compromise of staff users' admin sessions.… | |
| Aplazada | Alta (7.3) | 0.26% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections against stored cross-site scripting. Any staff user, including Contributors, could store scripts in post content that ran when another staff user opened the post in the editor,… | |
| Aplazada | Alta (8.8) | 0.25% | — | GhostAI | 5/10/2026 | 6/10/2026 | Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attacker-controlled website, resulting in arbitrary commands being run on the… | |
| Aplazada | Alta (8.6) | 0.65% | — | GhostAI | 2/10/2026 | 2/10/2026 | Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme translation file loading. Attackers with administrator access can upload a crafted theme containing malicious translation files to execute arbitrary code on the Ghost… | |
| Aplazada | Media (6.9) | 0.37% | — | GhostAI | 2/10/2026 | 2/10/2026 | Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to read JSON files outside the active theme directory. Attackers can manipulate the locale setting to load JSON files elsewhere on the server, exposing server configuration… | |
| Aplazada | Alta (7.7) | 0.31% | — | GhostAI | 2/10/2026 | 6/10/2026 | Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges. | |
| Aplazada | Baja (2.3) | 0.21% | — | GhostAI | 2/10/2026 | 2/10/2026 | Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relative ordering of other staff users' password hashes. Authenticated staff users can query the Admin API to infer hash ordering, though this does not directly reveal hashes… |