41 Total advisories
41 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 5.3
npm

CVE-2026-53949

Ghost Content API filter bypass reveals private fields

MEDIUM 4.0
npm

CVE-2026-70595

Ghost: Server-Side Request Forgery Mitigation Issue

MEDIUM 4.3
npm

CVE-2026-70596

Ghost: Cross-Site Scripting in Feature Image Captions

MEDIUM 5.3
npm

CVE-2026-59817

Ghost: Paid gift memberships obtainable at minimal cost via the donations feature

MEDIUM 5.3
npm

CVE-2026-53947

Ghost: Member existence leak via magic link sign-in response

MEDIUM 6.7
npm

CVE-2026-70594

Ghost: Session Fixation in Ghost Admin

MEDIUM 6.6
npm

CVE-2026-70593

Ghost: Theme Upload Path Traversal

MEDIUM 5.5
npm

CVE-2026-70592

Ghost: Database Backup Path Traversal

MEDIUM 4.8
npm

CVE-2026-70590

Ghost: Blind Password Hash Disclosure in Ghost Admin API

MEDIUM 4.1
npm

CVE-2026-70591

Ghost: Server-Side Request Forgery in Image Fetching

MEDIUM 5.8
npm

CVE-2026-53944

Ghost: Private IP filtering bypass to make server-side requests to internal services

MEDIUM 5.4
npm

CVE-2026-53946

Ghost: Mobiledoc image-size fetch SSRF

MEDIUM 4.0
npm

CVE-2026-53945

Ghost: Server-side request forgery via DNS rebinding in external request handling

MEDIUM 5.0
npm

CVE-2026-70588

Ghost: Cross-Site Scripting in Universal Import

MEDIUM 5.4
npm

CVE-2026-53948

Ghost: File Upload Content-Type Spoofing

MEDIUM 4.8
npm

CVE-2026-70589

Ghost: Archived Offers can be Redeemed

MEDIUM 6.5
npm

CVE-2021-39192

Privilege escalation: all users can access Admin-level API keys

HIGH 8.5
npm

CVE-2022-41654

ghost vulnerable to unauthorized newsletter modification via improper access controls

MEDIUM 6.8
npm

CVE-2021-29484

DOM XSS in Theme Preview

CRITICAL 9.6
npm

CVE-2026-53943

Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

CRITICAL 9.4
npm

CVE-2026-26980

Ghost has a SQL injection in Content API

HIGH 7.5
npm

CVE-2026-29784

Ghost has incomplete CSRF protections around OTC use

HIGH 7.6
npm

CVE-2026-29053

Ghost Vulnerable to Remote Code Execution via Malicious Themes

HIGH 8.8
npm

CVE-2026-24778

Ghost vulnerable to XSS via malicious Portal preview links

HIGH 8.1
npm

CVE-2026-22595

Ghost has Staff Token permission bypass

MEDIUM 6.7
npm

CVE-2026-22596

Ghost has SQL Injection in Members Activity Feed

UNKNOWN
npm

CVE-2026-22597

Ghost has SSRF via External Media Inliner

HIGH 8.1
npm

CVE-2026-22594

Ghost has Staff 2FA bypass

UNKNOWN
npm

CVE-2025-9862

Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark

MEDIUM 6.5
npm

CVE-2024-43409

Ghost's improper authentication allows access to member information and actions

MEDIUM 6.5
npm

CVE-2024-23724

Ghost has possible Cross-site Scripting issue

CRITICAL 9.8
npm

CVE-2022-28397

Arbitrary file upload in Ghost

MEDIUM 6.1
npm

CVE-2024-23725

Cross-site Scripting in Ghost

MEDIUM 4.9
npm

CVE-2023-40028

Ghost vulnerable to arbitrary file read via symlinks in content import

HIGH 7.5
npm

CVE-2023-32235

Path Traversal in Ghost

HIGH 7.5
npm

CVE-2023-31133

Ghost vulnerable to information disclosure of private API fields

CRITICAL 9.8
npm

CVE-2022-27139

Arbitrary file upload in Ghost

HIGH 8.1
npm

CVE-2020-8134

Server-side request forgery in Ghost CMS

MEDIUM 6.6
npm

GHSA-7v28-g2pq-ggg8

Ghost vulnerable to remote code execution in locale setting change

MEDIUM 6.5
npm

GHSA-65p7-pjj8-ggmr

Member account takeover

MEDIUM 5.8
npm

GHSA-wfrj-qqc2-83cm

Remote command injection when using sendmail email transport

Ready to move

Start Securing

Free, no credit card | First findings in minutes