ghost has 18 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 17 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 16. The median CVSS is 5.3 (medium), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-918 (5).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 17 prev 0
Worst active — by depth score
CVE-2022-28397Critical· 9.8An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file55CVE-2026-53943Critical· 9.6Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header53CVE-2026-70594Medium· 6.7Ghost is a Node.js content management system37CVE-2026-70593Medium· 6.6Ghost is a Node.js content management system36CVE-2026-53944Medium· 5.8Ghost: Private IP filtering bypass to make server-side requests to internal services32
ghost vulnerabilities
CVEs affecting ghost, newest first. Open any entry for full detail, references, and exploit status.
18 CVEsRSS
CVE-2026-70595Medium· 4.0Ghost is a Node.js content management system
Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost serve…
CVE-2026-70596Medium· 4.3Ghost is a Node.js content management system
Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin …
CVE-2026-53949Medium· 5.3Ghost Content API filter bypass reveals private fields
Ghost Content API filter bypass reveals private fields
CVE-2026-70593Medium· 6.6Ghost is a Node.js content management system
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation t…
CVE-2026-70594Medium· 6.7Ghost is a Node.js content management system
Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another v…
CVE-2026-53947Medium· 5.3Ghost: Member existence leak via magic link sign-in response
Ghost: Member existence leak via magic link sign-in response
CVE-2026-59817Medium· 5.3Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
CVE-2026-70588Medium· 5.0Ghost is a Node.js content management system
Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.
CVE-2026-53948Medium· 5.4Ghost: File Upload Content-Type Spoofing
Ghost: File Upload Content-Type Spoofing
CVE-2026-70589Medium· 4.8Ghost is a Node.js content management system
Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.
CVE-2026-53944Medium· 5.8Ghost: Private IP filtering bypass to make server-side requests to internal services
Ghost: Private IP filtering bypass to make server-side requests to internal services
CVE-2026-53945Medium· 4.0Ghost: Server-side request forgery via DNS rebinding in external request handling
Ghost: Server-side request forgery via DNS rebinding in external request handling
CVE-2026-53946Medium· 5.4Ghost: Mobiledoc image-size fetch SSRF
Ghost: Mobiledoc image-size fetch SSRF
CVE-2026-70590Medium· 4.8Ghost is a Node.js content management system
Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead…
CVE-2026-70591Medium· 4.1Ghost is a Node.js content management system
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was re…
CVE-2026-70592Medium· 5.5Ghost is a Node.js content management system
Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issu…
CVE-2026-53943Critical· 9.6Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
CVE-2022-28397Critical· 9.8An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be upl…