Ghost · Ghost · CVE-2024-23725
**Name of the Vulnerable Software and Affected Versions**
Ghost versions prior to 5.76.0
**Description**
The issue allows for cross-site scripting (XSS) via a post excerpt in excerpt.js, where an XSS payload can be rendered in post summaries. There have been reports of increased actor activities targeting this issue.
**Recommendations**
For versions prior to 5.76.0, update to version 5.76.0 or later to resolve the issue. As a temporary workaround, consider restricting the rendering of post excerpts in excerpt.js to minimize the risk of exploitation.