Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Ghost — Vulnerabilities & Security Advisories 76

All 76 CVE vulnerabilities found in Ghost, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Ghost, the open-source publishing platform, focusing on software weakness classes and associated advisories. It collects known security defects affecting the product, covering the full historical range of disclosed issues from initial release to current versions. Readers can track the vendor's security advisories, analyze specific weakness categories, and review the product's complete vulnerability history to assess risk trends and patching needs.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-104418 Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files CWE-22 7.2 High 2026-10-02
CVE-2026-104417 Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting CWE-22 4.9 Medium 2026-10-02
CVE-2026-104416 Ghost 4.39.0 before 6.64.0 Invite Token Disclosure via Admin API CWE-203 7.5 High 2026-10-02
CVE-2026-104415 Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API CWE-203 3.1 Low 2026-10-02
CVE-2026-104414 Ghost from 2.5.0 before 6.64.0 Stored XSS via oEmbed Photo Responses CWE-79 8.1 High 2026-10-02
CVE-2026-104413 Ghost 5.94.0 before 6.64.0 Stored XSS via Bookmark Card Images CWE-79 7.3 High 2026-10-02
CVE-2026-104411 Ghost 6.22.1 before 6.64.0 Stored XSS via Local Storage File Uploads CWE-79 7.3 High 2026-10-02
CVE-2026-104412 Ghost 0.5.0 before 6.64.0 Privilege Escalation via Staff Role Assignment CWE-269 4.3 Medium 2026-10-02
CVE-2026-103291 Ghost 3.20.2 before 6.51.0 SSRF via image-size fetch CWE-918 6.4 Medium 2026-10-01
CVE-2026-103292 Ghost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_head CWE-79 8.0 High 2026-10-01
CVE-2026-103290 Ghost 6.14.0 before 6.27.0 Path Traversal via ImageSize CWE-35 3.8 Low 2026-10-01
CVE-2026-103289 Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comments CWE-943 6.5 Medium 2026-10-01
CVE-2026-103288 Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comment Like CWE-639 6.5 Medium 2026-10-01
CVE-2026-103287 Ghost 1.18.0 before 6.27.0 Server-Side Request Forgery via Webhook CWE-918 2.7 Low 2026-10-01
CVE-2026-103286 Ghost 2.21.0 before 6.56.0 Privilege Escalation via Notifications CWE-266 7.3 High 2026-10-01
CVE-2026-103285 Ghost 5.19.0 before 6.57.1 Cross-Site Request Forgery CWE-352 4.3 Medium 2026-10-01
CVE-2026-103284 Ghost 5.125.1 before 6.57.1 Information Disclosure via Feedback CWE-863 4.3 Medium 2026-10-01
CVE-2026-103283 Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling CWE-613 8.1 High 2026-10-01
CVE-2026-103281 Ghost 3.23.0 before 6.23.0 API Key Exposure via Admin API CWE-201 5.4 Medium 2026-10-01
CVE-2026-103282 Ghost 0.5.0 before 6.23.0 Multiple Account Creation via Invite Token CWE-362 4.3 Medium 2026-10-01
CVE-2026-103280 Ghost 0.8.0 before 6.23.0 Information Disclosure via Setup Endpoint CWE-201 5.3 Medium 2026-10-01
CVE-2026-103279 Ghost 3.10.0 before 6.34.0 Session Invalidation Bypass CWE-613 6.8 Medium 2026-10-01
CVE-2026-103277 Ghost 2.5.0 before 6.34.0 Untrusted Script Execution via oEmbed CWE-79 8.1 High 2026-10-01
CVE-2026-103278 Ghost 5.8.0 before 6.34.0 Staff Account Takeover via Admin iframe CWE-23 7.3 High 2026-10-01
CVE-2026-103276 Ghost before 6.20.0 File Read via URL Encoding Bypass CWE-173 5.3 Medium 2026-10-01
CVE-2026-103275 Ghost 5.42.2 before 6.58.0 Password Hash Disclosure CWE-203 4.3 Medium 2026-10-01
CVE-2026-103274 Ghost 5.3.0 before 6.58.0 Unauthenticated Comment Read CWE-862 5.3 Medium 2026-10-01
CVE-2026-103273 Ghost 4.3.0 before 6.58.0 Incorrect Authorization via Staff Token CWE-863 4.3 Medium 2026-10-01
CVE-2026-103272 Ghost 2.10.0 before 6.63.0 Staff Enumeration via Content API CWE-203 7.5 High 2026-10-01
CVE-2026-103271 Ghost 4.0.0 before 6.63.0 Restricted Content Bypass CWE-863 7.5 High 2026-10-01

All 76 known CVE vulnerabilities affecting Ghost with full Chinese analysis, references, and POCs where available.