VulnSea

ghost has 18 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 17 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 16. The median CVSS is 5.3 (medium), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-918 (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.3
Publish → KEV
Last 90 days
17 prev 0

Products

  • ghost 18
18
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

ghost vulnerabilities

CVEs affecting ghost, newest first. Open any entry for full detail, references, and exploit status.

18 CVEsRSS

CVE-2026-70595Medium· 4.0
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost serve…

Sunlitghost · ghostEPSS 0.18%via NVD
CVE-2026-70596Medium· 4.3
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin …

Sunlitghost · ghostEPSS 0.18%via NVD
CVE-2026-53949Medium· 5.3
1mo ago

Ghost Content API filter bypass reveals private fields

Ghost Content API filter bypass reveals private fields

Sunlitghost · ghostEPSS 0.36%via GHSA
CVE-2026-70593Medium· 6.6
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation t…

Sunlitghost · ghostEPSS 0.29%via NVD
CVE-2026-70594Medium· 6.7
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another v…

Sunlitghost · ghostEPSS 0.16%via NVD
CVE-2026-53947Medium· 5.3
1mo ago

Ghost: Member existence leak via magic link sign-in response

Ghost: Member existence leak via magic link sign-in response

Sunlitghost · ghostEPSS 0.34%via GHSA
CVE-2026-59817Medium· 5.3
1mo ago

Ghost: Paid gift memberships obtainable at minimal cost via the donations feature

Ghost: Paid gift memberships obtainable at minimal cost via the donations feature

Sunlitghost · ghostEPSS 0.40%via GHSA
CVE-2026-70588Medium· 5.0
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.

Sunlitghost · ghostEPSS 0.26%via NVD
CVE-2026-53948Medium· 5.4
1mo ago

Ghost: File Upload Content-Type Spoofing

Ghost: File Upload Content-Type Spoofing

Sunlitghost · ghostEPSS 0.23%via GHSA
CVE-2026-70589Medium· 4.8
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.

Sunlitghost · ghostEPSS 0.17%via NVD
CVE-2026-53944Medium· 5.8
1mo ago

Ghost: Private IP filtering bypass to make server-side requests to internal services

Ghost: Private IP filtering bypass to make server-side requests to internal services

Sunlitghost · ghostEPSS 0.33%via GHSA
CVE-2026-53945Medium· 4.0
1mo ago

Ghost: Server-side request forgery via DNS rebinding in external request handling

Ghost: Server-side request forgery via DNS rebinding in external request handling

Sunlitghost · ghostEPSS 0.21%via GHSA
CVE-2026-53946Medium· 5.4
1mo ago

Ghost: Mobiledoc image-size fetch SSRF

Ghost: Mobiledoc image-size fetch SSRF

Sunlitghost · ghostEPSS 0.21%via GHSA
CVE-2026-70590Medium· 4.8
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead…

Sunlitghost · ghostEPSS 0.19%via NVD
CVE-2026-70591Medium· 4.1
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was re…

Sunlitghost · ghostEPSS 0.23%via NVD
CVE-2026-70592Medium· 5.5
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issu…

Sunlitghost · ghostEPSS 0.30%via NVD
CVE-2026-53943Critical· 9.6
2mo ago

Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

Midnightghost · ghostEPSS 0.45%via GHSA
CVE-2022-28397Critical· 9.8
4y ago

An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file

An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be upl…

Midnightghost · ghostEPSS 3.5%via NVD
ghost vulnerabilities (CVEs) · VulnSea