Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Ghost — Vulnerabilities & Security Advisories 76

All 76 CVE vulnerabilities found in Ghost, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Ghost, the open-source publishing platform, focusing on software weakness classes and associated advisories. It collects known security defects affecting the product, covering the full historical range of disclosed issues from initial release to current versions. Readers can track the vendor's security advisories, analyze specific weakness categories, and review the product's complete vulnerability history to assess risk trends and patching needs.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-103271 Ghost 4.0.0 before 6.63.0 Restricted Content Bypass CWE-863 7.5 High 2026-10-01
CVE-2026-103268 Ghost 1.0.0 before 6.62.0 Suspension Bypass via Password Reset CWE-862 8.8 High 2026-10-01
CVE-2026-103266 Ghost 5.2.0 before 6.62.0 Unauthenticated Stripe Checkout Account Modification CWE-863 7.1 High 2026-10-01
CVE-2026-103267 Ghost 0.5.0 before 6.62.0 Arbitrary Email Registration via Staff Invite CWE-807 4.3 Medium 2026-10-01
CVE-2026-72596 Ghost Foundation Ghost - Broken Access Control CWE-284 8.1 High 2026-08-11
CVE-2026-70596 Ghost: Cross-Site Scripting in Feature Image Captions CWE-79 4.3 Medium 2026-08-05
CVE-2026-70595 Ghost: Server-Side Request Forgery Mitigation Issue CWE-918 4.0 Medium 2026-08-05
CVE-2026-70594 Ghost: Session Fixation in Ghost Admin CWE-384 6.7 Medium 2026-08-04
CVE-2026-70593 Ghost: Theme Upload Path Traversal CWE-22 6.6 Medium 2026-08-04
CVE-2026-70592 Ghost: Database Backup Path Traversal CWE-22 5.5 Medium 2026-08-04
CVE-2026-70591 Ghost: Server-Side Request Forgery in Image Fetching CWE-918 4.1 Medium 2026-08-04
CVE-2026-70590 Ghost: Blind Password Hash Disclosure in Ghost Admin API CWE-200 4.8 Medium 2026-08-04
CVE-2026-70589 Ghost: Archived Offers can be Redeemed CWE-20 4.8 Medium 2026-08-04
CVE-2026-70588 Ghost: Cross-Site Scripting in Universal Import CWE-79 5.0 Medium 2026-08-04
CVE-2026-59817 Ghost: Paid gift memberships obtainable at minimal cost via the donations feature CWE-472 5.3 Medium 2026-07-09
CVE-2026-53943 Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header CWE-524 9.6 Critical 2026-06-24
CVE-2026-53944 Ghost: Private IP filtering bypass to make server-side requests to internal services CWE-184 5.8 Medium 2026-06-24
CVE-2026-53945 Ghost: Server-side request forgery via DNS rebinding in external request handling CWE-367 4.0 Medium 2026-06-24
CVE-2026-53946 Ghost: Mobiledoc image-size fetch SSRF CWE-918 5.4 Medium 2026-06-24
CVE-2026-53947 Ghost: Member existence leak via magic link sign-in response CWE-204 5.3 Medium 2026-06-24
CVE-2026-53948 Ghost: File Upload Content-Type Spoofing CWE-434 5.4 Medium 2026-06-24
CVE-2026-53949 Ghost Content API filter bypass reveals private fields CWE-200 5.3 Medium 2026-06-24
CVE-2026-53950 @tryghost/activitypub: XSS in Ghost's ActivityPub client CWE-79 7.5 High 2026-06-24
CVE-2026-29784 Ghost: Incomplete CSRF protections around OTC use CWE-352 7.5 High 2026-03-07
CVE-2026-29053 Ghost Vulnerable to Remote Code Execution via Malicious Themes CWE-74 7.7 High 2026-03-05
CVE-2026-26365 Akamai Ghost 环境问题漏洞 CWE-444 4.0 Medium 2026-02-23
CVE-2026-26980 Ghost has a SQL Injection in its Content API CWE-89 9.4 Critical 2026-02-20
CVE-2026-24778 Ghost vulnerable to XSS via malicious Portal preview links CWE-79 8.8 High 2026-01-27
CVE-2026-22597 Ghost has SSRF via External Media Inliner CWE-918 6.5 - 2026-01-10
CVE-2026-22596 Ghost has SQL Injection in Members Activity Feed CWE-89 6.7 Medium 2026-01-10

All 76 known CVE vulnerabilities affecting Ghost with full Chinese analysis, references, and POCs where available.