← Back to browse · API

CVE-2022-41654

Severity
CRITICAL
CVSS
9.6
EPSS
0.18914
Risk score
45.02
CISA KEV
No
PoC
No
Published
2022-12-23
Modified
2025-04-14
First seen
2026-08-07
Aliases
EUVD-2022-7303, GHSA-9GH8-WP53-CCC6
Products
TryGhost:Ghost 5.9.4
Sources
euvd EUVD-2022-7303

Description

An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.

References