cbcvebase.

Tryghost Ghost vulnerabilities

85 known vulnerabilities affecting tryghost/ghost.

Total CVEs
85
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH30MEDIUM46LOW7

Vulnerabilities

Page 3 of 5
CVE-2026-103266P4HIGHCVSS 7.1≥ 5.2.0, < 6.62.02026-10-01
CVE-2026-103266 [HIGH] CWE-863 CVE-2026-103266: Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authenticatio Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription to an existing member, modify that member's name, and inject content into newsletters sent to the member. Depending on the recipient's email client, the injected content may be rendere
nvd
CVE-2024-43409P4MEDIUMCVSS 6.5v>= 4.46.0 < 5.89.52024-08-20
CVE-2024-43409 [MEDIUM] CWE-284 CVE-2024-43409: Ghost is a Node.js content management system. Improper authentication on some endpoints used for mem Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.
nvd
CVE-2026-53944P4MEDIUMCVSS 5.8v>= 6.0.9, < 6.21.12026-06-24
CVE-2026-53944 [MEDIUM] CWE-184 CVE-2026-53944: Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external reque Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address. This vulnerability is fixed in 6.21.1.
nvd
CVE-2026-105680P4MEDIUMCVSS 6.5v>= 5.81.0, < 6.60.02026-10-05
CVE-2026-105680 [MEDIUM] CWE-862 CVE-2026-105680: Ghost is a Node.js content management system. From 5.81.0 until 6.60.0, staff with the Author role c Ghost is a Node.js content management system. From 5.81.0 until 6.60.0, staff with the Author role could delete posts and pages that they did not author. This issue is fixed in version 6.60.0.
nvd
CVE-2026-53949P4MEDIUMCVSS 5.3v>= 5.46.1, < 6.21.22026-06-24
CVE-2026-53949 [MEDIUM] CWE-200 CVE-2026-53949: Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to fi Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute force attack. If SQLite was used as the database password hashes were fully accessible. If MySQL was used as the database the passwo
nvd
CVE-2026-103276P4MEDIUMCVSS 5.3fixed in 6.20.02026-10-01
CVE-2026-103276 [MEDIUM] CWE-173 CVE-2026-103276: Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows una Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL encoding to bypass extension validation and access sensitive theme files.
nvd
CVE-2026-24778P4MEDIUMCVSS 6.1v@tryghost/portal >= 2.29.1, < 2.51.5v@tryghost/portal >= 2.52.0, < 2.57.1+2 more2026-01-27
CVE-2026-24778 [MEDIUM] CWE-79 CVE-2026-24778: Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0. Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0.0 through 6.14.0, an attacker was able to craft a malicious link that, when accessed by an authenticated staff user or member, would execute JavaScript with the victim's permissions, potentially leading to account takeover. Ghost Portal versions 2.29.1
nvd
CVE-2026-103281P4MEDIUMCVSS 5.4≥ 3.23.0, < 6.23.02026-10-01
CVE-2026-103281 [MEDIUM] CWE-201 CVE-2026-103281: Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts. An authenticated low-privilege staff user can read API keys returned by the Admin API, which are intended to be available only to higher-privileged users.
nvd
CVE-2026-59817P4MEDIUMCVSS 5.3v>= 6.27.0, < 6.44.02026-07-09
CVE-2026-59817 [MEDIUM] CWE-472 CVE-2026-59817: Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation che Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing money from a site or its members. This issue is fixed
nvd
CVE-2026-53947P4MEDIUMCVSS 5.3v>= 5.18.0, < 6.21.12026-06-24
CVE-2026-53947 [MEDIUM] CWE-204 CVE-2026-53947: Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses f Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a registered member of a Ghost site. This vulnerability is fixed in 6.21.1.
nvd
CVE-2026-70594P4MEDIUMCVSS 6.7v>= 2.2.0, < 6.54.12026-08-04
CVE-2026-70594 [MEDIUM] CWE-384 CVE-2026-70594: Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidat Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. This issue is fixed in version 6.54.1.
nvd
CVE-2026-53946P4MEDIUMCVSS 5.4v>= 6.19.4, < 6.21.12026-06-24
CVE-2026-53946 [MEDIUM] CWE-918 CVE-2026-53946: Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Gho Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch missing image dimensions by issuing an outbound HTTP request to the URL stored on an image card — without restricting that URL to trusted image hosts. An authenticated staff user able to create or edit posts could therefore point an i
nvd
CVE-2026-103274P4MEDIUMCVSS 5.3≥ 5.3.0, < 6.58.02026-10-01
CVE-2026-103274 [MEDIUM] CWE-862 CVE-2026-103274: Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private m Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.
nvd
CVE-2026-103280P4MEDIUMCVSS 5.3≥ 0.8.0, < 6.23.02026-10-01
CVE-2026-103280 [MEDIUM] CWE-201 CVE-2026-103280: Ghost from version 0.8.0 before 6.23.0 contains an information disclosure vulnerability in its setup Ghost from version 0.8.0 before 6.23.0 contains an information disclosure vulnerability in its setup endpoint: the endpoint responds to unauthenticated requests with the site owner's email address, allowing any remote visitor to obtain it.
nvd
CVE-2026-104417P4MEDIUMCVSS 4.9≥ 1.20.0, < 6.64.02026-10-02
CVE-2026-104417 [MEDIUM] CWE-22 CVE-2026-104417: Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file lo Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to read JSON files outside the active theme directory. Attackers can manipulate the locale setting to load JSON files elsewhere on the server, exposing server configuration secrets.
nvd
CVE-2026-70592P4MEDIUMCVSS 5.5v>= 1.20.1, < 6.54.12026-08-04
CVE-2026-70592 [MEDIUM] CWE-22 CVE-2026-70592: Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issues. The database export endpoint failed to reject path separators in the caller-supplied filename. This issue is fix
nvd
CVE-2026-53948P4MEDIUMCVSS 5.4v>= 6.19.4, < 6.21.12026-06-24
CVE-2026-53948 [MEDIUM] CWE-434 CVE-2026-53948: Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of t Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origi
nvd
CVE-2026-103269P4MEDIUMCVSS 5.3≥ 5.3.0, < 6.62.02026-10-01
CVE-2026-103269 [MEDIUM] CWE-862 CVE-2026-103269: Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an auth Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an authenticated site member to read the excerpts of posts they do not have access to (gated content).
nvd
CVE-2026-105676P4MEDIUMCVSS 4.9v>= 1.20.0, < 6.64.02026-10-05
CVE-2026-105676 [MEDIUM] CWE-22 CVE-2026-105676: Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to read JSON files outside of the active theme's directory, potentially exposing server configuration secrets. This issue is fixed in version 6.64.0.
nvd
CVE-2026-103267P4MEDIUMCVSS 4.3≥ 0.5.0, < 6.62.02026-10-01
CVE-2026-103267 [MEDIUM] CWE-807 CVE-2026-103267: Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptan Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. Attackers can accept leaked invite tokens with attacker-controlled email addresses, or legitimate recipients can register with unintended email providers.
nvd
Tryghost Ghost vulnerabilities | cvebase