CVE-2021-29484 is a Cross-Site Scripting (XSS) vulnerability affecting Ghost CMS versions 4.0.0 through 4.3.2, stemming from an unused endpoint. With a CVSS score of 6.8 (Medium), it allows untrusted users to gain Ghost Admin access if a logged-in user clicks a malicious link, leading to high confidentiality and integrity impact without requiring credentials. While Ghost(Pro) has been patched and no exploitation evidence exists there, self-hosted instances remain vulnerable. There is no evidence of active exploitation, but Nuclei templates exist, and the vulnerability has a high FAUCET Risk Score of 99/100, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.3.3CPE matchmatch criteria | cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.