6.6.0
14 years ago
3 days ago
Known vulnerabilities in the ghost package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version | 
|---|---|
 ghost is a publishing platform Affected versions of this package are vulnerable to Access Restriction Bypass that allows contributors to view draft posts of other users via the  NOTE: The vendor's position is that this behavior has no security impact. How to fix Access Restriction Bypass? There is no fixed version for   | >=0.4.2-rc1  | 
 ghost is a publishing platform Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the  How to fix Cross-site Scripting (XSS)? There is no fixed version for   | >=0.0.0  | 
 ghost is a publishing platform Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the  How to fix Cross-site Scripting (XSS)? There is no fixed version for   | >=0.0.0  | 
 ghost is a publishing platform Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the  How to fix Cross-site Scripting (XSS)? There is no fixed version for   | >=0.0.0  | 
 ghost is a publishing platform Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the  How to fix Cross-site Scripting (XSS)? There is no fixed version for   | >=0.0.0  |