TryGhost Ghost
40 known vulnerabilities in TryGhost Ghost, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-105646 CVSS 4.9 medium Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, a crafted content import file could cause excessive CPU usage…
- CVE-2026-105645 CVSS 4.9 medium Ghost is a Node.js content management system. From 5.37.0 until 6.67.0, a crafted request to the external media inliner could cause…
- CVE-2026-105644 CVSS 6.8 medium Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in content imports were stored without…
- CVE-2026-105643 CVSS 7.3 high Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections…
- CVE-2026-105642 CVSS 8.8 high Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a…
- CVE-2026-104418 CVSS 8.6 high Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by…
- CVE-2026-104417 CVSS 6.9 medium Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated…
- CVE-2026-104416 CVSS 7.7 high Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret…
- CVE-2026-104415 CVSS 2.3 low Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to…
- CVE-2026-104414 CVSS 8.6 high Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into…
- CVE-2026-104413 CVSS 8.5 high Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to…
- CVE-2026-104412 CVSS 5.3 medium Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign…
- CVE-2026-104411 CVSS 8.5 high Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading…
- CVE-2026-103292 CVSS 8.6 high Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted by the…
- CVE-2026-103291 CVSS 5.3 medium Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery vulnerability in image dimension refetching that allows…
- CVE-2026-103290 CVSS 5.1 medium Ghost versions 6.14.0 through versions prior to 6.27.0 contain a path traversal vulnerability in the ImageSize service. Insufficient input…
- CVE-2026-103289 CVSS 7.1 high Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenticated members to access…
- CVE-2026-103288 CVSS 7.1 high Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before…
- CVE-2026-103287 CVSS 5.1 medium Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webhooks feature that allows staff users to…
- CVE-2026-103286 CVSS 8.5 high Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows…
- CVE-2026-103285 CVSS 5.3 medium Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows…
- CVE-2026-103284 CVSS 5.3 medium Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows…
- CVE-2026-103283 CVSS 8.6 high Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other…
- CVE-2026-103282 CVSS 5.3 medium Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts…
- CVE-2026-103281 CVSS 5.3 medium Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff…
- CVE-2026-103280 CVSS 6.9 medium Ghost from version 0.8.0 before 6.23.0 contains an information disclosure vulnerability in its setup endpoint: the endpoint responds to…
- CVE-2026-103279 CVSS 7.6 high Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session…
- CVE-2026-103278 CVSS 8.5 high Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff…
- CVE-2026-103277 CVSS 8.6 high Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to…
- CVE-2026-103276 CVSS 6.9 medium Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme…