Ghost
This hub aggregates every CVE we track for Ghost, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
50
CVEs tracked
6
Critical
11
High
0
In CISA KEV
Severity distribution
MEDIUM32HIGH11CRITICAL6LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
5
2
2
0
0
8
1
9
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Ghost.
- CVE-2026-70596Ghost: Cross-Site Scripting in Feature Image Captions4.3
- CVE-2026-70595Ghost: Server-Side Request Forgery Mitigation Issue4.0
- CVE-2026-70594Ghost: Session Fixation in Ghost Admin6.7
- CVE-2026-70593Ghost: Theme Upload Path Traversal6.6
- CVE-2026-70592Ghost: Database Backup Path Traversal5.5
- CVE-2026-70591Ghost: Server-Side Request Forgery in Image Fetching4.1
- CVE-2026-70590Ghost: Blind Password Hash Disclosure in Ghost Admin API4.8
- CVE-2026-70589Ghost: Archived Offers can be Redeemed4.8
- CVE-2026-70588Ghost: Cross-Site Scripting in Universal Import5.0
- CVE-2026-59817Ghost: Paid gift memberships obtainable at minimal cost via the donations feature5.3
- CVE-2026-53943Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header9.6
- CVE-2026-53944Ghost: Private IP filtering bypass to make server-side requests to internal services5.8
- CVE-2026-53945Ghost: Server-side request forgery via DNS rebinding in external request handling4.0
- CVE-2026-53946Ghost: Mobiledoc image-size fetch SSRF5.4
- CVE-2026-53947Ghost: Member existence leak via magic link sign-in response5.3
Product normalization is registry-driven with AI assist and human review. How it works