CVE-2026-105677High· 7.2▾ TwilightGhost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This i…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This issue is fixed in version 6.64.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105676Medium· 4.9Ghost is a Node.js content management system
CVE-2026-104418High· 7.2Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme translation file loading
CVE-2026-105679High· 7.3Ghost is a Node.js content management system
CVE-2026-105678Medium· 4.3Ghost is a Node.js content management system
CVE-2026-105650High· 8.1Ghost is a Node.js content management system
CVE-2026-105651High· 7.3Ghost is a Node.js content management system