CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-28397

Critical · CVSS 9.8

Ghost CMS — Arbitrary File Upload RCE (CWE-434)

CVSS
9.8
nvd
EPSS
3.44%
88th pct
KEV
No
Class
oss containerizable
CWE-434

Description

An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional.

Search profile — drives PoC discovery

Symbols file upload moduleghost cms uploadv4.42.0crafted filearbitrary code executionimage uploadtheme upload
Keywords CVE-2022-28397Ghost CMSarbitrary file uploadghost 4.42.0file upload RCEghost cms exploitghost cms unrestricted file uploadghost CMS PoCghost CMS code execution
Versions: ghost <= 4.42.0

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

Bitnami ghost 4.42.0 → 4.42.1
npm ghost 0 → ∞

References

Status: enriched · ingested 2026-07-05T18:00:39.000Z · profiled 2026-07-05T18:30:39.000Z