Ghost
TryGhost · 85 CVEs
Ghost: Path Traversal Vulnerability in Ghost ImageSize Service
Oct 5, 2026
Ghost: Stored XSS via File Uploads on Local Storage
Oct 5, 2026
Ghost: Password Hash Ordering Disclosure in Ghost Admin API
Oct 5, 2026
Ghost: Server-Side Request Forgery in Bookmark Fetching
Oct 5, 2026
Ghost: Server-Side Request Forgery in Webhook Trigger
Oct 5, 2026
Ghost: Authorization Bypass in Comments Feature
Oct 5, 2026
Ghost: Authorization Issue Allowed Author Role to Delete any Post
Oct 5, 2026
Ghost: Editors Could Promote Staff Users to Their Own Role
Oct 5, 2026
Ghost: Remote Code Execution via Theme Translation Files
Oct 5, 2026
Ghost: Regular Expression Denial of Service in External Media Inliner
Oct 5, 2026
Ghost: Remote Code Execution via Bookmark Card Images
Oct 5, 2026
Ghost: Path Traversal via Locale Setting
Oct 5, 2026
Ghost: Invite Token Disclosure in Ghost Admin API
Oct 5, 2026
Ghost: Stored XSS via Bookmark Card Images
Oct 5, 2026
Ghost: Stored XSS via oEmbed Photo Responses
Oct 5, 2026
Ghost: Stored XSS via SVG Uploads Bypassing Sanitization
Oct 5, 2026
Ghost: Private IP Filtering Bypass via IPv6 Transition Addresses
Oct 5, 2026
Ghost: Regular Expression Denial of Service in Content Import
Oct 5, 2026
Ghost: Stored XSS via SVG Files in Content Imports
Oct 5, 2026
Ghost: Stored XSS via Embed Card Previews
Oct 5, 2026
Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files
Oct 2, 2026
Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting
Oct 2, 2026
Ghost 4.39.0 before 6.64.0 Invite Token Disclosure via Admin API
Oct 2, 2026
Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API
Oct 2, 2026
Ghost from 2.5.0 before 6.64.0 Stored XSS via oEmbed Photo Responses
Oct 2, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-105683 | Ghost: Path Traversal Vulnerability in Ghost ImageSize Service | LOW | 0.31% | Oct 5, 2026 |
| CVE-2026-105679 | Ghost: Stored XSS via File Uploads on Local Storage | HIGH | 0.24% | Oct 5, 2026 |
| CVE-2026-105652 | Ghost: Password Hash Ordering Disclosure in Ghost Admin API | LOW | 0.26% | Oct 5, 2026 |
| CVE-2026-105647 | Ghost: Server-Side Request Forgery in Bookmark Fetching | MEDIUM | 0.23% | Oct 5, 2026 |
| CVE-2026-105682 | Ghost: Server-Side Request Forgery in Webhook Trigger | LOW | 0.24% | Oct 5, 2026 |
| CVE-2026-105681 | Ghost: Authorization Bypass in Comments Feature | MEDIUM | 0.26% | Oct 5, 2026 |
| CVE-2026-105680 | Ghost: Authorization Issue Allowed Author Role to Delete any Post | MEDIUM | 0.27% | Oct 5, 2026 |
| CVE-2026-105678 | Ghost: Editors Could Promote Staff Users to Their Own Role | MEDIUM | 0.20% | Oct 5, 2026 |
| CVE-2026-105677 | Ghost: Remote Code Execution via Theme Translation Files | HIGH | 0.52% | Oct 5, 2026 |
| CVE-2026-105645 | Ghost: Regular Expression Denial of Service in External Media Inliner | MEDIUM | 0.33% | Oct 5, 2026 |
| CVE-2026-105642 | Ghost: Remote Code Execution via Bookmark Card Images | HIGH | 0.25% | Oct 5, 2026 |
| CVE-2026-105676 | Ghost: Path Traversal via Locale Setting | MEDIUM | 0.40% | Oct 5, 2026 |
| CVE-2026-105675 | Ghost: Invite Token Disclosure in Ghost Admin API | HIGH | 0.39% | Oct 5, 2026 |
| CVE-2026-105651 | Ghost: Stored XSS via Bookmark Card Images | HIGH | 0.30% | Oct 5, 2026 |
| CVE-2026-105650 | Ghost: Stored XSS via oEmbed Photo Responses | HIGH | 0.33% | Oct 5, 2026 |
| CVE-2026-105649 | Ghost: Stored XSS via SVG Uploads Bypassing Sanitization | HIGH | 0.30% | Oct 5, 2026 |
| CVE-2026-105648 | Ghost: Private IP Filtering Bypass via IPv6 Transition Addresses | MEDIUM | 0.30% | Oct 5, 2026 |
| CVE-2026-105646 | Ghost: Regular Expression Denial of Service in Content Import | MEDIUM | 0.33% | Oct 5, 2026 |
| CVE-2026-105644 | Ghost: Stored XSS via SVG Files in Content Imports | MEDIUM | 0.32% | Oct 5, 2026 |
| CVE-2026-105643 | Ghost: Stored XSS via Embed Card Previews | HIGH | 0.27% | Oct 5, 2026 |
| CVE-2026-104418 | Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files | HIGH | 0.65% | Oct 2, 2026 |
| CVE-2026-104417 | Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting | MEDIUM | 0.37% | Oct 2, 2026 |
| CVE-2026-104416 | Ghost 4.39.0 before 6.64.0 Invite Token Disclosure via Admin API | HIGH | 0.31% | Oct 2, 2026 |
| CVE-2026-104415 | Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API | LOW | 0.21% | Oct 2, 2026 |
| CVE-2026-104414 | Ghost from 2.5.0 before 6.64.0 Stored XSS via oEmbed Photo Responses | HIGH | 0.28% | Oct 2, 2026 |
Showing 1 to 25 of 85 CVEs