CMS
TryGhost/Ghost
Independent technology for modern publishing, memberships, subscriptions and newsletters.
#journalism#publishing#blogging#javascript#web-application#cms#nodejs#ghost
スコア
60
/ 100
Star
52,810
Fork
11,550
Open Issue
70
サイズ
457MB
言語
JavaScript ★
最終push
0 日前
Docker
—
採点内訳
過去CVE 16件 (やや多い)
✓直近 push: 0 日前
✓得意言語 (JavaScript)
✓オープンissue 70件
—大規模 (457MB)
—Docker 未対応
—50k–100k: 上級 (★52,810)
—※ 各項目の重みは「採点ルール」を参照。合計は 0 で底打ち。
過去の SecurityAdvisory (18 件)
- Incomplete CSRF protections around OTC use
- Remote Code Execution via Malicious Themes
- SQL injection in Content API
- XSS via malicious Portal preview links
- SQL Injection in Members Activity Feed
- SSRF via External Media Inliner
- Staff Token permission bypass
- Staff 2FA bypass
- SSRF via oEmbed Bookmark
- Improper authentication allows access to member information and actions
- Arbitrary file read via symlinks in content import
- Information disclosure of private API fields
- Unauthorized Newsletter Modification
- Remote code execution in locale setting change
- Member account takeover
- Remote command injection when using sendmail email transport
- Privilege escalation: all users can access Admin-level API keys
- DOM XSS in Theme Preview