cbcvebase.
CVE-2026-22596
published 2026-01-10

CVE-2026-22596: Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's…

PriorityP349high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.41%
33.0th percentile
Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's /ghost/api/admin/members/events endpoint allows users with authentication credentials for the Admin API to execute arbitrary SQL. This issue has been patched in versions 5.130.6 and 6.11.0.

Affected

6 ranges
VendorProductVersion rangeFixed in
ghostghost>= 5.105.0 < 5.130.65.130.6
ghostghost>= 5.90.0 < 5.130.65.130.6
ghostghost>= 6.0.0 < 6.11.06.11.0
ghostghost>= 6.0.0 < 6.11.06.11.0
tryghostghost
tryghostghost
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.