Tryghost Ghost vulnerabilities
85 known vulnerabilities affecting tryghost/ghost.
Total CVEs
85
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH30MEDIUM46LOW7
Vulnerabilities
Page 4 of 5
CVE-2026-105645P4MEDIUMCVSS 4.9v>= 5.37.0, < 6.67.02026-10-05
CVE-2026-105645 [MEDIUM] CWE-1333 CVE-2026-105645: Ghost is a Node.js content management system. From 5.37.0 until 6.67.0, a crafted request to the ext
Ghost is a Node.js content management system. From 5.37.0 until 6.67.0, a crafted request to the external media inliner could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0.
nvd
CVE-2026-103273P4MEDIUMCVSS 4.3≥ 4.3.0, < 6.58.02026-10-01
CVE-2026-103273 [MEDIUM] CWE-863 CVE-2026-103273: Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privil
Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level.
nvd
CVE-2026-105646P4MEDIUMCVSS 4.9v>= 4.0.0, < 6.67.02026-10-05
CVE-2026-105646 [MEDIUM] CWE-1333 CVE-2026-105646: Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, a crafted content import file
Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, a crafted content import file could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0.
nvd
CVE-2026-70590P4MEDIUMCVSS 4.8fixed in 6.54.12026-08-04
CVE-2026-70590 [MEDIUM] CWE-200 CVE-2026-70590: Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak
Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification should have prevented an attacker from logging in with
nvd
CVE-2026-70588P4MEDIUMCVSS 5.0v>= 5.26.0, < 6.54.12026-08-04
CVE-2026-70588 [MEDIUM] CWE-79 CVE-2026-70588: Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature
Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.
nvd
CVE-2026-105648P4MEDIUMCVSS 4.0v>= 6.0.9, < 6.65.02026-10-05
CVE-2026-105648 [MEDIUM] CWE-184 CVE-2026-105648: Ghost is a Node.js content management system. From 6.0.9 until 6.65.0, a validation issue allowed so
Ghost is a Node.js content management system. From 6.0.9 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network on some network configurations. A successful attack would not result in any response data be
nvd
CVE-2026-70589P4MEDIUMCVSS 4.8v>= 4.22.0, < 6.54.12026-08-04
CVE-2026-70589 [MEDIUM] CWE-20 CVE-2026-70589: Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check a
Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.
nvd
CVE-2026-103282P4MEDIUMCVSS 4.3≥ 0.5.0, < 6.23.02026-10-01
CVE-2026-103282 [MEDIUM] CWE-362 CVE-2026-103282: Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance me
Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a single invite token. Attackers can exploit this race condition by submitting concurrent requests with the same invitation token to create duplicate user accounts.
nvd
CVE-2026-103275P4MEDIUMCVSS 4.3≥ 5.42.2, < 6.58.02026-10-01
CVE-2026-103275 [MEDIUM] CWE-203 CVE-2026-103275: Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in the Admin API bulk po
Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in the Admin API bulk post and page edit and delete endpoints, which accept filters on restricted fields such as authors.password, because of an incomplete fix for CVE-2026-70590. Staff-level attackers can infer other staff users' password hashes from which filters match a
nvd
CVE-2026-104412P4MEDIUMCVSS 4.3≥ 0.5.0, < 6.64.02026-10-02
CVE-2026-104412 [MEDIUM] CWE-269 CVE-2026-104412: Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the
Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to other staff despite lacking permission to do so. An authenticated Editor or Super Editor can promote Author and Contributor users to Editor or Super Editor.
nvd
CVE-2026-103284P4MEDIUMCVSS 4.3≥ 5.125.1, < 6.57.12026-10-01
CVE-2026-103284 [MEDIUM] CWE-863 CVE-2026-103284: Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Adm
Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks.
nvd
CVE-2026-105647P4MEDIUMCVSS 4.0v>= 6.54.1, < 6.65.02026-10-05
CVE-2026-105647 [MEDIUM] CWE-367 CVE-2026-105647: Ghost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed s
Ghost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This issue is fi
nvd
CVE-2026-105678P4MEDIUMCVSS 4.3v>= 0.5.0, < 6.64.02026-10-05
CVE-2026-105678 [MEDIUM] CWE-269 CVE-2026-105678: Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor o
Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role. This issue is fixed in version 6.64.0.
nvd
CVE-2026-70591P4MEDIUMCVSS 4.1v>= 0.10.0, < 6.54.12026-08-04
CVE-2026-70591 [MEDIUM] CWE-918 CVE-2026-70591: Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forger
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on internal hosts. This issue is fixed in version 6.54.1
nvd
CVE-2026-70595P4MEDIUMCVSS 4.0v>= 6.26.0, < 6.54.12026-08-05
CVE-2026-70595 [MEDIUM] CWE-918 CVE-2026-70595: Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed s
Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This vulnerability
nvd
CVE-2026-70596P4MEDIUMCVSS 4.3v>= 4.9.0, < 6.54.12026-08-05
CVE-2026-70596 [MEDIUM] CWE-79 CVE-2026-70596: Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue all
Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin session, resulting in privilege escalation. This issue is fixed in 6.54.1.
nvd
CVE-2026-53945P4MEDIUMCVSS 4.0v>= 6.0.9, < 6.21.12026-06-24
CVE-2026-53945 [MEDIUM] CWE-367 CVE-2026-53945: Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for
Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue external fetches. This vulnerability is fixed in 6.21.1.
nvd
CVE-2026-103285P4MEDIUMCVSS 4.3≥ 5.19.0, < 6.57.12026-10-01
CVE-2026-103285 [MEDIUM] CWE-352 CVE-2026-103285: Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the p
Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows attackers to submit feedback on behalf of logged-in users. Attackers can craft a malicious link to the feedback page that automatically submits feedback when visited by authenticated members without their knowl
nvd
CVE-2026-103290P4LOWCVSS 3.8≥ 6.14.0, < 6.27.02026-10-01
CVE-2026-103290 [LOW] CWE-35 CVE-2026-103290: Ghost versions 6.14.0 through versions prior to 6.27.0 contain a path traversal vulnerability in the
Ghost versions 6.14.0 through versions prior to 6.27.0 contain a path traversal vulnerability in the ImageSize service. Insufficient input validation of user-supplied file paths may allow authenticated staff users to access local files outside the intended data storage directories on the server.
nvd
CVE-2026-105683P4LOWCVSS 3.8v>= 6.14.0, < 6.27.02026-10-05
CVE-2026-105683 [LOW] CWE-35 CVE-2026-105683: Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue ma
Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue may have allowed staff users to access local files outside the intended data storage directories on the server. This issue is fixed in version 6.27.0.
nvd