VulnSea

TryGhost has 27 CVEs on record. Disclosure cadence is accelerating: 27 in the last 90 days against 0 in the 90 before. The busiest recent month was October 2026 with 26. The median CVSS is 6.4 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (4) and CWE-79 (3). Most affected products: Ghost (26), @tryghost/activitypub (1).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
6.4
Publish → KEV
—
Last 90 days
27 prev 0

Products

  • Ghost 26
  • @tryghost/activitypub 1
27
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

TryGhost vulnerabilities

CVEs affecting TryGhost, newest first. Open any entry for full detail, references, and exploit status.

27 CVEsRSS

CVE-2026-103292High· 8.0
today

Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted by the {{ghost_head}} helper

Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted by the {{ghost_head}} helper. An authenticated user with limited privileges can inject unescaped content that is …

▾ TwilightTryGhost · Ghostvia NVD
CVE-2026-103291Medium· 6.4
today

Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery vulnerability in image dimension refetching that allows authenticated staff users to trigger outbound HTTP requests to arbitrary URLs

Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery vulnerability in image dimension refetching that allows authenticated staff users to trigger outbound HTTP requests to arbitrary URLs. Attackers can point ima…

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103290Low· 3.8
today

Ghost versions 6.14.0 through versions prior to 6.27.0 contain a path traversal vulnerability in the ImageSize service

Ghost versions 6.14.0 through versions prior to 6.27.0 contain a path traversal vulnerability in the ImageSize service. Insufficient input validation of user-supplied file paths may allow authenticated staff users to access local files o…

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103289Medium· 6.5
today

Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenticated members to access comments they are not authorized to view, resulting in disclosure of restricted comment data.

Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenticated members to access comments they are not authorized to view, resulting in disclosure of restricted comment data.

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103288Medium· 6.5
today

Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1

Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that the…

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103287Low· 2.7
today

Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webhooks feature that allows staff users to probe internal hosts

Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webhooks feature that allows staff users to probe internal hosts. Attackers with staff privileges can craft webhook requests to access interna…

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103286High· 7.3
today

Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff roles

Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff roles. Attackers with low-privilege staff acces…

▾ TwilightTryGhost · Ghostvia NVD
CVE-2026-103285Medium· 4.3
today

Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows attackers to submit feedback on behalf of logged-in users

Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows attackers to submit feedback on behalf of logged-in users. Attackers can craft a malicious link to…

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103284Medium· 4.3
today

Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data

Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback e…

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103283High· 8.1
today

Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication

Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff …

▾ TwilightTryGhost · Ghostvia NVD
CVE-2026-103282Medium· 4.3
today

Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a single invite token

Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a single invite token. Attackers can exploit this race condition by submitting c…

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103281Medium· 5.4
today

Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts

Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts. An authenticated low-privilege staff user can read API keys returned by the Admin API, which ar…

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103280Medium· 5.3
today

Ghost from version 0.8.0 before 6.23.0 contains an information disclosure vulnerability in its setup endpoint: the endpoint responds to unauthenticated requests with the site owner's email address, allowing any remote visitor to obtain it.

Ghost from version 0.8.0 before 6.23.0 contains an information disclosure vulnerability in its setup endpoint: the endpoint responds to unauthenticated requests with the site owner's email address, allowing any remote visitor to obtain it.

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103279Medium· 6.8
today

Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change

Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access to user accounts even after the associated user changes their password.

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103278High· 7.3
today

Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff user accounts

Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff user accounts. Attackers with content publishing privileges can craft malicious pages that, when vi…

▾ TwilightTryGhost · Ghostvia NVD
CVE-2026-103277High· 8.1
today

Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts

Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in…

▾ TwilightTryGhost · Ghostvia NVD
CVE-2026-103276Medium· 5.3
today

Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata

Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL encoding to bypass extension validation and access sen…

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103275Medium· 4.3
today

Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in the Admin API bulk post and page edit and delete endpoints, which accept filters on restricted fields such as authors.password, because of an incomplete fix f…

Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in the Admin API bulk post and page edit and delete endpoints, which accept filters on restricted fields such as authors.password, because of an incomplete fix f…

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103274Medium· 5.3
today

Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode

Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103273Medium· 4.3
today

Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions

Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit po…

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103272High· 7.5
today

Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data

Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data. Attackers can observe discrepancies in API metadata responses to enumerate sta…

▾ TwilightTryGhost · Ghostvia NVD
CVE-2026-103271High· 7.5
today

Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content

Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly querying the content API to retrieve res…

▾ TwilightTryGhost · Ghostvia NVD
CVE-2026-103269Medium· 5.3
today

Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an authenticated site member to read the excerpts of posts they do not have access to (gated content).

Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an authenticated site member to read the excerpts of posts they do not have access to (gated content).

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103268High· 8.8
today

Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset

Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform passwo…

▾ TwilightTryGhost · Ghostvia NVD
CVE-2026-103267Medium· 4.3
today

Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account

Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. Attackers can accept leaked invite tokens with attacker-co…

▾ SunlitTryGhost · Ghostvia NVD
CVE-2026-103266High· 7.1
today

Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription to an existing member, modify that member's name, and inject content i…

Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription to an existing member, modify that member's name, and inject content i…

▾ TwilightTryGhost · Ghostvia NVD
CVE-2026-53950High· 7.5
1mo ago

XSS in Ghost's ActivityPub client

XSS in Ghost's ActivityPub client

▾ Twilighttryghost · @tryghost/activitypubEPSS 0.35%via GHSA
TryGhost vulnerabilities (CVEs) · VulnSea