cbcvebase.

Tryghost Ghost vulnerabilities

85 known vulnerabilities affecting tryghost/ghost.

Total CVEs
85
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH30MEDIUM46LOW7

Vulnerabilities

Page 2 of 5
CVE-2026-104416P3HIGHCVSS 7.5≥ 4.39.0, < 6.64.02026-10-02
CVE-2026-104416 [HIGH] CWE-203 CVE-2026-104416: Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API th Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.
nvd
CVE-2026-105651P3HIGHCVSS 7.3v>= 5.94.0, < 6.64.02026-10-05
CVE-2026-105651 [HIGH] CWE-79 CVE-2026-105651: Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark car Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from an external website as bookmark icons or thumbnails. This allowed any staff user, including Contributors, to host arbitrary HTML on the site's domain, possibly resulting in compromise of other staff use
nvd
CVE-2026-105650P3HIGHCVSS 8.1v>= 2.5.0, < 6.64.02026-10-05
CVE-2026-105650 [HIGH] CWE-79 CVE-2026-105650: Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attac Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting in compromise of a staff user's admin session. This
nvd
CVE-2026-105649P3HIGHCVSS 7.3v>= 4.22.0, < 6.65.02026-10-05
CVE-2026-105649 [HIGH] CWE-79 CVE-2026-105649: Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issu
nvd
CVE-2026-103278P3HIGHCVSS 7.3≥ 5.8.0, < 6.34.02026-10-01
CVE-2026-103278 [HIGH] CWE-23 CVE-2026-103278: Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe tha Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff user accounts. Attackers with content publishing privileges can craft malicious pages that, when visited by active staff users, enable account takeover through improper input validation.
nvd
CVE-2021-39192P3HIGHCVSS 7.2v>= 4.0.0, < 4.10.02021-09-03
CVE-2021-39192 [HIGH] CWE-200 CVE-2021-39192: Ghost is a Node.js content management system. An error in the implementation of the limits service b Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint, leading to a privilege escalation vulnerability. This issue is patched in Ghost version 4.10.0. As a
nvd
CVE-2026-105679P3HIGHCVSS 7.3v>= 6.22.1, < 6.64.02026-10-05
CVE-2026-105679 [HIGH] CWE-79 CVE-2026-105679: Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from executing them. On sites using the default local storage adapter, this restriction was not applied, so files uploaded by any staff user were served with a content type derived from their file
nvd
CVE-2026-29784P3HIGHCVSS 8.8v>= 5.101.6, < 6.19.32026-03-07
CVE-2026-29784 [HIGH] CWE-352 CVE-2026-29784: Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protec Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to use OTCs in login sessions different from the requesting session. In some scenarios this might have made it easier for phishers to take over a Ghost site. This issue has been patched in version 6.19.3.
nvd
CVE-2026-53950P3HIGHCVSS 7.5fixed in 3.1.02026-06-24
CVE-2026-53950 [HIGH] CWE-79 CVE-2026-53950: @tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub clien @tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. This vulnerability is fixed in 3.1.0.
nvd
CVE-2026-103279P3MEDIUMCVSS 6.8≥ 3.10.0, < 6.34.02026-10-01
CVE-2026-103279 [MEDIUM] CWE-613 CVE-2026-103279: Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password chan Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access to user accounts even after the associated user changes their password.
nvd
CVE-2026-103291P3MEDIUMCVSS 6.4≥ 3.20.2, < 6.51.02026-10-01
CVE-2026-103291 [MEDIUM] CWE-918 CVE-2026-103291: Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery vulnerability in imag Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery vulnerability in image dimension refetching that allows authenticated staff users to trigger outbound HTTP requests to arbitrary URLs. Attackers can point image cards at attacker-controlled hosts or internal network endpoints to access metadata services and internal res
nvd
CVE-2026-104414P3HIGHCVSS 8.1≥ 2.5.0, < 6.64.02026-10-02
CVE-2026-104414 [HIGH] CWE-79 CVE-2026-104414: Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows atta Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embedding their URL stores scripts that run in the Ghost editor, published site, and newsletter emails, compromi
nvd
CVE-2026-105643P3HIGHCVSS 7.3v>= 6.34.0, < 6.67.02026-10-05
CVE-2026-105643 [HIGH] CWE-79 CVE-2026-105643: Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the G Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections against stored cross-site scripting. Any staff user, including Contributors, could store scripts in post content that ran when another staff user opened the post in the editor, potentially compromising that user’s a
nvd
CVE-2026-104413P3HIGHCVSS 7.3≥ 5.94.0, < 6.64.02026-10-02
CVE-2026-104413 [HIGH] CWE-79 CVE-2026-104413: Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows sta Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to host arbitrary HTML by abusing bookmark card image fetching. Attackers can create bookmark cards that store non-image files from external websites as icons or thumbnails to compromise other staff users' admin sessio
nvd
CVE-2026-105681P3MEDIUMCVSS 6.5v>= 5.9.0, < 6.44.12026-10-05
CVE-2026-105681 [MEDIUM] CWE-943 CVE-2026-105681: Ghost is a Node.js content management system. From 5.9.0 until 6.44.1, an input validation issue all Ghost is a Node.js content management system. From 5.9.0 until 6.44.1, an input validation issue allowed members to access comments they were not authorized to access. This issue is fixed in version 6.44.1.
nvd
CVE-2026-103289P3MEDIUMCVSS 6.5≥ 5.9.0, < 6.44.12026-10-01
CVE-2026-103289 [MEDIUM] CWE-943 CVE-2026-103289: Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allow Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenticated members to access comments they are not authorized to view, resulting in disclosure of restricted comment data.
nvd
CVE-2026-103288P3MEDIUMCVSS 6.5≥ 5.9.0, < 6.44.12026-10-01
CVE-2026-103288 [MEDIUM] CWE-639 CVE-2026-103288: Ghost, an open-source publishing platform, contains an input validation flaw in its comment like fea Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment en
nvd
CVE-2026-104411P3HIGHCVSS 7.3≥ 6.22.1, < 6.64.02026-10-02
CVE-2026-104411 [HIGH] CWE-79 CVE-2026-104411: Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows sta Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served with extension-derived content types on the default local storage adapter. Attackers can upload script-bearing files to the site's domain to compromise other staff users' admin sessions.
nvd
CVE-2026-105644P3MEDIUMCVSS 6.8v>= 4.0.0, < 6.67.02026-10-05
CVE-2026-105644 [MEDIUM] CWE-79 CVE-2026-105644: Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in conten Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in content imports were stored without sanitization. An attacker who convinced an Administrator to import a crafted file could host scripts on the site's domain, possibly resulting in compromise of staff users' admin sessions. This issue is fixed in version 6
nvd
CVE-2026-70593P3MEDIUMCVSS 6.6v>= 0.10.0, < 6.54.12026-08-04
CVE-2026-70593 [MEDIUM] CWE-22 CVE-2026-70593: Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom th Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation through custom theme upload path traversal in LocalStorageBase and theme storage name handling. This issue is fixed
nvd
Tryghost Ghost vulnerabilities | cvebase