Tryghost Ghost vulnerabilities
85 known vulnerabilities affecting tryghost/ghost.
Total CVEs
85
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH30MEDIUM46LOW7
Vulnerabilities
Page 1 of 5
CVE-2026-26980P1HIGHCVSS 7.5ExploitedPoCv>= 3.24.0, < 6.19.12026-02-20
CVE-2026-26980 [HIGH] CWE-89 CVE-2026-26980: Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated a
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.
nvd
CVE-2026-29053P2CRITICALCVSS 9.8PoCv>= 0.7.2, < 6.19.12026-03-05
CVE-2026-29053 [CRITICAL] CWE-74 CVE-2026-29053: Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted mal
Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.
nvd
CVE-2023-40028P2MEDIUMCVSS 6.5PoCfixed in 5.59.12023-08-15
CVE-2023-40028 [MEDIUM] CWE-22 CVE-2023-40028: Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnera
Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system. Site administrators can check for exploitation of this issue by looking for unk
nvd
CVE-2026-22594P3HIGHCVSS 8.1PoCv>= 6.0.0, < 6.11.0v>= 5.105.0, < 5.130.62026-01-10
CVE-2026-22594 [HIGH] CWE-287 CVE-2026-22594: Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through
Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA. This issue has been patched in versions 5.130.6 and 6.11.0.
nvd
CVE-2023-31133P2HIGHCVSS 7.5fixed in 5.46.12023-05-08
CVE-2023-31133 [HIGH] CWE-200 CVE-2023-31133: Ghost is an app for new-media creators with tools to build a website, publish content, send newslett
Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid subscriptions to members. Prior to version 5.46.1, due to a lack of validation when filtering on the public API endpoints, it is possible to reveal private fields via a brute force attack.
Ghost(Pro) has already been patched. Mainta
nvd
CVE-2021-29484P3MEDIUMCVSS 6.1PoCv>= 4.0.0, < 4.3.32021-04-29
CVE-2021-29484 [MEDIUM] CWE-79 CVE-2021-29484: Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vuln
Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted users gaining access to Ghost Admin. Attackers can gain access by getting logged in users to click a link containing malicious code. Users do not need to enter credentials and may not know they've visited a malicious site. Ghost(Pro
nvd
CVE-2026-103268P2HIGHCVSS 8.8≥ 1.0.0, < 6.62.02026-10-01
CVE-2026-103268 [HIGH] CWE-862 CVE-2026-103268: Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended st
Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset operations to regain active account access and restore their original privileges.
nvd
CVE-2026-103283P3HIGHCVSS 8.1≥ 6.20.0, < 6.57.12026-10-01
CVE-2026-103283 [HIGH] CWE-613 CVE-2026-103283: Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticat
Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized acces
nvd
CVE-2026-103271P3HIGHCVSS 7.5≥ 4.0.0, < 6.63.02026-10-01
CVE-2026-103271 [HIGH] CWE-863 CVE-2026-103271: Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthentica
Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly querying the content API to retrieve restricted posts without authentication.
nvd
CVE-2026-105642P3HIGHCVSS 8.8v>= 6.56.0, < 6.67.02026-10-05
CVE-2026-105642 [HIGH] CWE-94 CVE-2026-105642: Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library
Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attacker-controlled website, resulting in arbitrary commands being run on the Ghost server. This issue is fixed
nvd
CVE-2026-22595P3HIGHCVSS 8.1v>= 6.0.0, < 6.11.0v>= 5.121.0, < 5.130.62026-01-10
CVE-2026-22595 [HIGH] CWE-863 CVE-2026-22595: Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through
Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token authentication allowed certain endpoints to be accessed that were only intended to be accessible via Staff Session authentication. External systems that have been authenticated via Staff Tokens f
nvd
CVE-2026-53943P3CRITICALCVSS 9.6v>= 4.0.0, < 6.37.02026-06-24
CVE-2026-53943 [CRITICAL] CWE-524 CVE-2026-53943: Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared cach
Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being shared between different visitors, an unauthenticated user could send an x-ghost-preview header that altered the rendered frontend response. In affected cache configurations, that response could be stored
nvd
CVE-2026-103272P3HIGHCVSS 7.5≥ 2.10.0, < 6.63.02026-10-01
CVE-2026-103272 [HIGH] CWE-203 CVE-2026-103272: Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content AP
Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data. Attackers can observe discrepancies in API metadata responses to enumerate staff members and extract sensitive information without authentication.
nvd
CVE-2026-104418P3HIGHCVSS 7.2≥ 6.10.3, < 6.64.02026-10-02
CVE-2026-104418 [HIGH] CWE-22 CVE-2026-104418: Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authentic
Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme translation file loading. Attackers with administrator access can upload a crafted theme containing malicious translation files to execute arbitrary code on the Ghost server.
nvd
CVE-2026-105675P3HIGHCVSS 7.5v>= 4.39.0, < 6.64.02026-10-05
CVE-2026-105675 [HIGH] CWE-203 CVE-2026-105675: Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission
Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret token of pending invites, including invites for roles with higher privileges than their own. This could allow a staff user to escalate their privileges by accepting a pending invite. This issue is
nvd
CVE-2026-22596P3HIGHCVSS 7.2v>= 6.0.0, < 6.11.0v>= 5.90.0, < 5.130.62026-01-10
CVE-2026-22596 [HIGH] CWE-89 CVE-2026-22596: Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6
Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's /ghost/api/admin/members/events endpoint allows users with authentication credentials for the Admin API to execute arbitrary SQL. This issue has been patched in versions 5.130.6 and 6.11.0.
nvd
CVE-2026-105677P3HIGHCVSS 7.2v>= 6.10.3, < 6.64.02026-10-05
CVE-2026-105677 [HIGH] CWE-22 CVE-2026-105677: Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost
Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This issue is fixed in version 6.64.0.
nvd
CVE-2026-103286P3HIGHCVSS 7.3≥ 2.21.0, < 6.56.02026-10-01
CVE-2026-103286 [HIGH] CWE-266 CVE-2026-103286: Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notific
Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff roles. Attackers with low-privilege staff access can exploit the notifications system to gain elevated privileges without proper authorization checks.
nvd
CVE-2026-103292P3HIGHCVSS 8.0≥ 0.5.3, < 6.50.02026-10-01
CVE-2026-103292 [HIGH] CWE-79 CVE-2026-103292: Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the J
Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted by the {{ghost_head}} helper. An authenticated user with limited privileges can inject unescaped content that is rendered as script in the published page, potentially leading to compromise of a staff user's admin session when th
nvd
CVE-2026-103277P3HIGHCVSS 8.1≥ 2.5.0, < 6.34.02026-10-01
CVE-2026-103277 [HIGH] CWE-79 CVE-2026-103277: Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the o
Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in the context of a staff user's admin session, potentially compromising administrative access.
nvd
1 / 5Next →