Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-105694 — Penpot: Stored XSS via Unsanitised SVG Uploads

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG media whose scripts, event-handler attributes, and foreignObjec…

penpot | Remote | Cross-Site Scripting
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.3 MEDIUM
CVE-2026-105693 — Penpot: Anonymous share-link token disclosure & page-scope bypass via get-view-only-bundle

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with…

penpot | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.4 MEDIUM
CVE-2026-105692 — Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Links They Did…

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and verifies only that the caller can edit the parent fi…

penpot | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
9.9 CRITICAL
CVE-2026-105691 — Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and execute…

penpot | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.9 MEDIUM
CVE-2026-105690 — Penpot: Server-side session not invalidated on logout; stale auth-token cookie remains va…

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the corresponding server-side session. A previously captured …

penpot | Remote | Authentication
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.0 MEDIUM
CVE-2026-105689 — Penpot: SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) in webhook de…

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java InetAddress predicates that do not classify NAT64, 6to4, or Teredo addresses a…

penpot | Remote | Server-Side Request Forgery
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.7 MEDIUM
CVE-2026-105688 — Penpot: Team admin can escalate to owner via team invitation (missing owner-role guard on…

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role bec…

penpot | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
4.9 MEDIUM
CVE-2026-105687 — Penpot: A team admin (non-owner) can remove the team owner via ::delete-team-member — mis…

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves but does not protect the t…

penpot | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.3 MEDIUM
CVE-2026-105686 — Penpot: Repeated chunk index causes temporary-storage amplification

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the chunked media upload RPC validates that a chunk index is in range but neither rejects an already stored index nor replac…

penpot | Remote | Denial of Service
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
4.3 MEDIUM
CVE-2026-105684 — Penpot: Share-link page-scope escape — comment RPCs leak comment content, author identity…

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and get-comments RPC commands use check-comment-permissions! but do not apply t…

penpot | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
3.8 LOW
CVE-2026-105683 — Ghost: Path Traversal Vulnerability in Ghost ImageSize Service

Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue may have allowed staff users to access local files outside the intended data storage directories on t…

ghost | Remote | Path Traversal
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
2.7 LOW
CVE-2026-105682 — Ghost: Server-Side Request Forgery in Webhook Trigger

Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an SSRF vulnerability in the webhooks feature allowed staff users to probe internal hosts from the Ghost server. This issue is …

ghost | Remote | Server-Side Request Forgery
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.5 MEDIUM
CVE-2026-105681 — Ghost: Authorization Bypass in Comments Feature

Ghost is a Node.js content management system. From 5.9.0 until 6.44.1, an input validation issue allowed members to access comments they were not authorized to access. This issue is fixed in version …

ghost | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.5 MEDIUM
CVE-2026-105680 — Ghost: Authorization Issue Allowed Author Role to Delete any Post

Ghost is a Node.js content management system. From 5.81.0 until 6.60.0, staff with the Author role could delete posts and pages that they did not author. This issue is fixed in version 6.60.0.

ghost | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.3 HIGH
CVE-2026-105679 — Ghost: Stored XSS via File Uploads on Local Storage

Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from executing them. On sites using the defa…

ghost | Remote | Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
4.3 MEDIUM
CVE-2026-105678 — Ghost: Editors Could Promote Staff Users to Their Own Role

Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not…

ghost | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.2 HIGH
CVE-2026-105677 — Ghost: Remote Code Execution via Theme Translation Files

Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on …

ghost | Remote | Path Traversal
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
4.9 MEDIUM
CVE-2026-105676 — Ghost: Path Traversal via Locale Setting

Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to read JSON files outside of…

ghost | Remote | Information Disclosure
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.5 HIGH
CVE-2026-105675 — Ghost: Invite Token Disclosure in Ghost Admin API

Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret token of pending invites, including invites …

ghost | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
3.1 LOW
CVE-2026-105652 — Ghost: Password Hash Ordering Disclosure in Ghost Admin API

Ghost is a Node.js content management system. From 0.7.2 until 6.64.0, any staff-level user was able to determine the relative ordering of other staff users' hashed passwords. This does not directly …

ghost | Remote | Information Disclosure
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
Showing 20 of 14497 Results