ghost vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-53949Mediumghost: Ghost Content API filter bypass reveals private fieldsCVE-2026-70596Mediumghost: Ghost: Cross-Site Scripting in Feature Image CaptionsCVE-2026-70595Mediumghost: Ghost: Server-Side Request Forgery Mitigation IssueCVE-2026-59817Mediumghost: Ghost: Paid gift memberships obtainable at minimal cost via the donations featureCVE-2026-53947Mediumghost: Ghost: Member existence leak via magic link sign-in responseCVE-2026-70594Mediumghost: Ghost: Session Fixation in Ghost AdminCVE-2026-70593Mediumghost: Ghost: Theme Upload Path TraversalCVE-2026-70592Mediumghost: Ghost: Database Backup Path TraversalCVE-2026-70591Mediumghost: Ghost: Server-Side Request Forgery in Image FetchingCVE-2026-70590Mediumghost: Ghost: Blind Password Hash Disclosure in Ghost Admin APICVE-2026-53946Mediumghost: Ghost: Mobiledoc image-size fetch SSRFCVE-2026-53945Mediumghost: Ghost: Server-side request forgery via DNS rebinding in external request handlingCVE-2026-53944Mediumghost: Ghost: Private IP filtering bypass to make server-side requests to internal servicesCVE-2026-70589Mediumghost: Ghost: Archived Offers can be RedeemedCVE-2026-53948Mediumghost: Ghost: File Upload Content-Type SpoofingCVE-2026-70588Mediumghost: Ghost: Cross-Site Scripting in Universal ImportCVE-2026-53943Criticalghost: Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview headerCVE-2026-29784Highghost: Ghost has incomplete CSRF protections around OTC useCVE-2026-29053Highghost: Ghost Vulnerable to Remote Code Execution via Malicious ThemesCVE-2026-26980Criticalghost: Ghost has a SQL injection in Content APICVE-2026-24778Highghost: Ghost vulnerable to XSS via malicious Portal preview linksCVE-2026-22596Mediumghost: Ghost has SQL Injection in Members Activity FeedCVE-2026-22597Mediumghost: Ghost has SSRF via External Media InlinerCVE-2026-22595Highghost: Ghost has Staff Token permission bypassCVE-2026-22594Highghost: Ghost has Staff 2FA bypass

Stop the waste.
Protect your environment with Kodem.