MEDIUM
Ghost: Cross-Site Scripting in Universal Import
Published Aug 4, 2026
5.0
MEDIUMCVSS 3.1
EPSS 0.43%
Description
Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.
Affected products
-
- Version >= 5.26.0, < 6.54.1StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
ghost
npm
Introduced 5.26.0 Fixed 6.54.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | ghost | 5.26.0 | 6.54.1 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52928 Advisory
- https://github.com/TryGhost/Ghost/commit/a8bea3a4ceec4c852b880f4885119453c3d8588e x_refsource_MISC
- https://github.com/TryGhost/Ghost/pull/29635 x_refsource_MISC
- https://github.com/TryGhost/Ghost/releases/tag/v6.54.1 x_refsource_MISC
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-2gx6-7gx2-wwcf x_refsource_CONFIRM
- https://github.com/advisories/GHSA-2gx6-7gx2-wwcf Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52928 | Advisory | |
| https://github.com/TryGhost/Ghost/commit/a8bea3a4ceec4c852b880f4885119453c3d8588e | x_refsource_MISC | |
| https://github.com/TryGhost/Ghost/pull/29635 | x_refsource_MISC | |
| https://github.com/TryGhost/Ghost/releases/tag/v6.54.1 | x_refsource_MISC | |
| https://github.com/TryGhost/Ghost/security/advisories/GHSA-2gx6-7gx2-wwcf | x_refsource_CONFIRM | |
| https://github.com/advisories/GHSA-2gx6-7gx2-wwcf | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 4, 2026
Updated Aug 5, 2026
Reserved Aug 4, 2026
Link CVE-2026-70588
CISA Vulnrichment
Updated Aug 5, 2026
ENISA EUVD
EUVD-2026-52928 GHSA-2GX6-7GX2-WWCF Assigner GitHub_M
Published Aug 4, 2026
Updated Aug 5, 2026
Exploited since n/a
Link EUVD-2026-52928