CVE-2024-23725: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
(updated )
Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries.
References
Detect and mitigate CVE-2024-23725 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →