Логотип exploitDog
bind:CVE-2026-22595
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-22595

Количество 3

Количество 3

nvd логотип

CVE-2026-22595

3 месяца назад

Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token authentication allowed certain endpoints to be accessed that were only intended to be accessible via Staff Session authentication. External systems that have been authenticated via Staff Tokens for Admin/Owner-role users would have had access to these endpoints. This issue has been patched in versions 5.130.6 and 6.11.0.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-22595

3 месяца назад

Ghost is a Node.js content management system. In versions 5.121.0 thro ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-9xg7-mwmp-xmjx

3 месяца назад

Ghost has Staff Token permission bypass

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-22595

Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token authentication allowed certain endpoints to be accessed that were only intended to be accessible via Staff Session authentication. External systems that have been authenticated via Staff Tokens for Admin/Owner-role users would have had access to these endpoints. This issue has been patched in versions 5.130.6 and 6.11.0.

CVSS3: 8.1
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-22595

Ghost is a Node.js content management system. In versions 5.121.0 thro ...

CVSS3: 8.1
0%
Низкий
3 месяца назад
github логотип
GHSA-9xg7-mwmp-xmjx

Ghost has Staff Token permission bypass

CVSS3: 8.1
0%
Низкий
3 месяца назад

Уязвимостей на страницу