41 Total advisories
41 Vulnerabilities
0 Malware
Vulnerabilities
MEDIUM 5.3
CVE-2026-53949
Ghost Content API filter bypass reveals private fields
MEDIUM 4.0
CVE-2026-70595
Ghost: Server-Side Request Forgery Mitigation Issue
MEDIUM 4.3
CVE-2026-70596
Ghost: Cross-Site Scripting in Feature Image Captions
MEDIUM 5.3
CVE-2026-59817
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
MEDIUM 5.3
CVE-2026-53947
Ghost: Member existence leak via magic link sign-in response
MEDIUM 6.7
CVE-2026-70594
Ghost: Session Fixation in Ghost Admin
MEDIUM 6.6
CVE-2026-70593
Ghost: Theme Upload Path Traversal
MEDIUM 5.5
CVE-2026-70592
Ghost: Database Backup Path Traversal
MEDIUM 4.8
CVE-2026-70590
Ghost: Blind Password Hash Disclosure in Ghost Admin API
MEDIUM 4.1
CVE-2026-70591
Ghost: Server-Side Request Forgery in Image Fetching
MEDIUM 5.8
CVE-2026-53944
Ghost: Private IP filtering bypass to make server-side requests to internal services
MEDIUM 5.4
CVE-2026-53946
Ghost: Mobiledoc image-size fetch SSRF
MEDIUM 4.0
CVE-2026-53945
Ghost: Server-side request forgery via DNS rebinding in external request handling
MEDIUM 5.0
CVE-2026-70588
Ghost: Cross-Site Scripting in Universal Import
MEDIUM 5.4
CVE-2026-53948
Ghost: File Upload Content-Type Spoofing
MEDIUM 4.8
CVE-2026-70589
Ghost: Archived Offers can be Redeemed
MEDIUM 6.5
CVE-2021-39192
Privilege escalation: all users can access Admin-level API keys
HIGH 8.5
CVE-2022-41654
ghost vulnerable to unauthorized newsletter modification via improper access controls
MEDIUM 6.8
CVE-2021-29484
DOM XSS in Theme Preview
CRITICAL 9.6
CVE-2026-53943
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
CRITICAL 9.4
CVE-2026-26980
Ghost has a SQL injection in Content API
HIGH 7.5
CVE-2026-29784
Ghost has incomplete CSRF protections around OTC use
HIGH 7.6
CVE-2026-29053
Ghost Vulnerable to Remote Code Execution via Malicious Themes
HIGH 8.8
CVE-2026-24778
Ghost vulnerable to XSS via malicious Portal preview links
HIGH 8.1
CVE-2026-22595
Ghost has Staff Token permission bypass
MEDIUM 6.7
CVE-2026-22596
Ghost has SQL Injection in Members Activity Feed
UNKNOWN
CVE-2026-22597
Ghost has SSRF via External Media Inliner
HIGH 8.1
CVE-2026-22594
Ghost has Staff 2FA bypass
UNKNOWN
CVE-2025-9862
Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark
MEDIUM 6.5
CVE-2024-43409
Ghost's improper authentication allows access to member information and actions
MEDIUM 6.5
CVE-2024-23724
Ghost has possible Cross-site Scripting issue
CRITICAL 9.8
CVE-2022-28397
Arbitrary file upload in Ghost
MEDIUM 6.1
CVE-2024-23725
Cross-site Scripting in Ghost
MEDIUM 4.9
CVE-2023-40028
Ghost vulnerable to arbitrary file read via symlinks in content import
HIGH 7.5
CVE-2023-32235
Path Traversal in Ghost
HIGH 7.5
CVE-2023-31133
Ghost vulnerable to information disclosure of private API fields
CRITICAL 9.8
CVE-2022-27139
Arbitrary file upload in Ghost
HIGH 8.1
CVE-2020-8134
Server-side request forgery in Ghost CMS
MEDIUM 6.6
GHSA-7v28-g2pq-ggg8
Ghost vulnerable to remote code execution in locale setting change
MEDIUM 6.5
GHSA-65p7-pjj8-ggmr
Member account takeover
MEDIUM 5.8
GHSA-wfrj-qqc2-83cm
Remote command injection when using sendmail email transport
Ready to move
Start Securing
Free, no credit card | First findings in minutes