tryghost
Web & CMS Pluginscommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting tryghost.
- CVE-2026-70596Ghost: Cross-Site Scripting in Feature Image Captions4.3
- CVE-2026-70595Ghost: Server-Side Request Forgery Mitigation Issue4.0
- CVE-2026-70594Ghost: Session Fixation in Ghost Admin6.7
- CVE-2026-70593Ghost: Theme Upload Path Traversal6.6
- CVE-2026-70592Ghost: Database Backup Path Traversal5.5
- CVE-2026-70591Ghost: Server-Side Request Forgery in Image Fetching4.1
- CVE-2026-70590Ghost: Blind Password Hash Disclosure in Ghost Admin API4.8
- CVE-2026-70589Ghost: Archived Offers can be Redeemed4.8
- CVE-2026-70588Ghost: Cross-Site Scripting in Universal Import5.0
- CVE-2026-25552Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header3.7
- CVE-2026-59817Ghost: Paid gift memberships obtainable at minimal cost via the donations feature5.3
- CVE-2026-53943Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header9.6
- CVE-2026-53944Ghost: Private IP filtering bypass to make server-side requests to internal services5.8
- CVE-2026-53945Ghost: Server-side request forgery via DNS rebinding in external request handling4.0
- CVE-2026-53946Ghost: Mobiledoc image-size fetch SSRF5.4