CVE-2026-103267
- EPSS 0.26%
- Veröffentlicht 01.10.2026 10:42:08
- Zuletzt bearbeitet 01.10.2026 17:17:18
Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. Attackers can accept leaked invite tokens with attacker-controlled emai...
CVE-2026-103266
- EPSS 0.3%
- Veröffentlicht 01.10.2026 10:42:07
- Zuletzt bearbeitet 06.10.2026 01:16:32
Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription to an existing member, modify that member's name, and inject content into newslette...
CVE-2026-72596
- EPSS 0.21%
- Veröffentlicht 11.08.2026 11:13:39
- Zuletzt bearbeitet 28.08.2026 18:51:39
A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the branch that handles the combined isAuthor and isDestr...
CVE-2026-29784
- EPSS 0.16%
- Veröffentlicht 07.03.2026 15:30:38
- Zuletzt bearbeitet 09.03.2026 20:06:23
Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to use OTCs in login sessions different from the requesting session. In some scenarios this might have m...
CVE-2026-29053
- EPSS 0.99%
- Veröffentlicht 05.03.2026 05:51:41
- Zuletzt bearbeitet 09.03.2026 18:40:22
Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.
CVE-2026-26980
- EPSS 69.33%
- Veröffentlicht 20.02.2026 01:00:51
- Zuletzt bearbeitet 26.05.2026 15:16:24
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.
CVE-2026-24778
- EPSS 0.26%
- Veröffentlicht 27.01.2026 21:57:45
- Zuletzt bearbeitet 02.02.2026 15:21:41
Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0.0 through 6.14.0, an attacker was able to craft a malicious link that, when accessed by an authenticated staff user or member, would execute JavaScrip...
CVE-2026-22597
- EPSS 0.27%
- Veröffentlicht 10.01.2026 02:57:36
- Zuletzt bearbeitet 29.04.2026 01:00:01
Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost’s media inliner mechanism allows staff users in possession of a valid authentication token for the Ghost Admin API to ...
CVE-2026-22596
- EPSS 0.42%
- Veröffentlicht 10.01.2026 02:57:19
- Zuletzt bearbeitet 15.01.2026 18:35:34
Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's /ghost/api/admin/members/events endpoint allows users with authentication credentials for the Admin API to execute a...
CVE-2026-22595
- EPSS 0.5%
- Veröffentlicht 10.01.2026 02:57:08
- Zuletzt bearbeitet 15.01.2026 18:34:49
Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token authentication allowed certain endpoints to be accessed that were only intended to be acces...