{"id":"CVE-2024-23725","aliases":["BIT-ghost-2024-23725","GHSA-fh38-9fgr-454w"],"url":"https://o3.security/vulnerability/CVE-2024-23725","summary":"Cross-site Scripting in Ghost","details":"Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries.","published":"2024-01-21T00:00:00Z","modified":"2026-08-12T03:51:27.925103503Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"ghost","fixedVersion":"5.76.0"}],"fix":{"url":"https://github.com/TryGhost/Ghost/pull/17190","label":"TryGhost/Ghost#17190"},"references":[{"type":"WEB","url":"https://github.com/TryGhost/Ghost/releases/tag/v5.76.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23725.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23725"},{"type":"FIX","url":"https://github.com/TryGhost/Ghost/pull/17190"},{"type":"WEB","url":"https://github.com/yunaycompany/Ghost/commit/64d67717f7c76c77b3908e15627f473e9ef34002"},{"type":"PACKAGE","url":"https://github.com/TryGhost/Ghost"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:27.925103503Z"}}