//
sign in
Post
by @danabra.mov
PostEmbed
by @danabra.mov
Record
by @jimpick.com
Record
by @atsui.org
+ new component
Post
Here's the writeup for CVE-2026-53943, a cache poisoning -> XSS vuln I found in Ghost CMS 👻 cryptocat.me/blog/researc...
7d
Root cause analysis of CVE-2026-53943 in Ghost CMS, an unauthenticated cache-poisoning XSS where one anonymous request poisons any caching layer in front of Ghost with attacker-controlled JavaScript t...
cryptocat.me
Ghost CMS Unauthenticated Cache-Poisoning XSS to Account Takeover via x-ghost-preview | CVE-2026-53943 | CryptoCat's Blog
CryptoCat