PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 21, 2026

Ghost CMS - User Enumeration

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3.5k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
6
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-41697
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigger this vulnerability.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Ghostby Ghost Foundation
5.9.4
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Ghost CMS - User Enumeration CVE-2022-41697 Scanner | S4E