Ghost CMS before 6.19.1 is vulnerable to a blind SQL injection in the /ghost/api/content/tags/ endpoint via the filter parameter. This template checks for the vulnerability by sending a boolean-based payload.
id: CVE-2026-26980
info:
name: Ghost CMS Content API - SQL Injection
author: domwhewell-sage
...