Tryghost Ghost vulnerabilities
85 known vulnerabilities affecting tryghost/ghost.
Total CVEs
85
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH30MEDIUM46LOW7
Vulnerabilities
Page 5 of 5
CVE-2026-105652P4LOWCVSS 3.1v>= 0.7.2, < 6.64.02026-10-05
CVE-2026-105652 [LOW] CWE-203 CVE-2026-105652: Ghost is a Node.js content management system. From 0.7.2 until 6.64.0, any staff-level user was able
Ghost is a Node.js content management system. From 0.7.2 until 6.64.0, any staff-level user was able to determine the relative ordering of other staff users' hashed passwords. This does not directly disclose password hashes, and does not provide a practical path to recovering a password. This issue is fixed in version 6.64.0.
nvd
CVE-2026-22597P4LOWCVSS 2.7v>= 6.0.0, < 6.11.0v>= 5.38.0, < 5.130.62026-01-10
CVE-2026-22597 [LOW] CWE-918 CVE-2026-22597: Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6
Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost’s media inliner mechanism allows staff users in possession of a valid authentication token for the Ghost Admin API to exfiltrate data from internal systems via SSRF. This issue has been patched in versions 5.130.6 and 6.11
nvd
CVE-2026-103287P4LOWCVSS 2.7≥ 1.18.0, < 6.27.02026-10-01
CVE-2026-103287 [LOW] CWE-918 CVE-2026-103287: Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webho
Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webhooks feature that allows staff users to probe internal hosts. Attackers with staff privileges can craft webhook requests to access internal network resources from the Ghost server.
nvd
CVE-2026-104415P4LOWCVSS 3.1≥ 0.7.2, < 6.64.02026-10-02
CVE-2026-104415 [LOW] CWE-203 CVE-2026-104415: Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API tha
Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relative ordering of other staff users' password hashes. Authenticated staff users can query the Admin API to infer hash ordering, though this does not directly reveal hashes or enable practical password reco
nvd
CVE-2026-105682P4LOWCVSS 2.7v>= 1.18.0, < 6.27.02026-10-05
CVE-2026-105682 [LOW] CWE-918 CVE-2026-105682: Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an SSRF vulnerability in the
Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an SSRF vulnerability in the webhooks feature allowed staff users to probe internal hosts from the Ghost server. This issue is fixed in version 6.27.0.
nvd
← Previous5 / 5