PatchSiren

TryGhost CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH TryGhost CVE published 2026-10-07

CVE-2026-105642

CVE-2026-105642 debrief based on CVE Program, NVD, and osv_dev records. The vulnerability is a remote code execution issue in Ghost's image processing library, allowing staff users to create bookmark cards for attacker-controlled websites, potentially leading to arbitrary command execution on the Ghost server. The vulnerability is present in Ghost from v6.56.0 up to v6.65.0 and is fixed in v6.67.0. Admini [truncated]

HIGH TryGhost CVE published 2026-10-07

CVE-2026-105643

CVE-2026-105643 debrief: Ghost Stored XSS via Embed Card Previews. A stored XSS vulnerability in Ghost allows staff users to store scripts in post content that can run when another staff user opens the post in the editor, potentially resulting in compromise of that user's admin session. This issue affects Ghost from v6.34.0 up to v6.65.0 and is fixed in v6.67.0. Self-hosted sites should leave the new `sec [truncated]

MEDIUM TryGhost CVE published 2026-10-07

CVE-2026-105644

CVE-2026-105644 debrief based on the supplied source corpus. The vulnerability is a stored XSS via SVG files in content imports in Ghost versions from 4.0.0 to 6.65.0. An attacker could host scripts on the site's domain, potentially compromising staff users' admin sessions. Defenders should assess exposure and prioritize updates to version 6.67.0 or later. This CVE record was published on 2026-10-07T20:43 [truncated]

MEDIUM TryGhost CVE published 2026-10-07

CVE-2026-105645

A crafted request to the external media inliner in Ghost could cause excessive CPU usage, making the server unresponsive. This requires Administrator access and affects Ghost versions from 5.37.0 up to 6.65.0. The issue is fixed in version 6.67.0. Defenders managing Ghost installations should assess exposure and prioritize updates, especially for self-hosted instances using Docker or Ghost-CLI. The vulner [truncated]

MEDIUM TryGhost CVE published 2026-10-07

CVE-2026-105646

CVE-2026-105646 is a Regular Expression Denial of Service (ReDoS) vulnerability in Ghost, a Node.js content management system. The vulnerability affects versions from 4.0.0 to 6.66.0 and allows an attacker with Administrator access to cause excessive CPU usage, making the Ghost server unresponsive. The issue is fixed in version 6.67.0. This vulnerability has the potential to impact the availability of the [truncated]

MEDIUM TryGhost CVE published 2026-10-07

CVE-2026-105647

A validation issue in Ghost allowed unauthenticated users to make limited HTTP requests to hosts in the Ghost server's internal network via Webmentions. A successful attack would not return response data. The vulnerability is present in Ghost from version 6.54.1 up to version 6.64.0, and is fixed in version 6.65.0. Defenders should assess exposure and prioritize updates, particularly for instances using W [truncated]

MEDIUM TryGhost CVE published 2026-10-07

CVE-2026-105648

A validation issue in Ghost allowed unauthenticated users to make limited HTTP requests to internal network hosts on some configurations. This vulnerability is present in Ghost from v6.0.9 up to v6.64.0 and is fixed in v6.65.0. The issue arises from inadequate validation, enabling attackers to bypass private IP filtering via IPv6 transition addresses. Defenders should assess exposure and prioritize updati [truncated]

HIGH TryGhost CVE published 2026-10-07

CVE-2026-105649

CVE-2026-105649: Ghost Stored XSS via SVG Uploads Bypassing Sanitization allows staff users, including Contributors, to host scripts on the site's domain, potentially compromising admin sessions. The vulnerability affects Ghost installations between versions 4.22.0 and 6.64.0. Updating to version 6.65.0 or later is recommended to mitigate this issue. Affected deployments should be identified, and owners a [truncated]

HIGH TryGhost CVE published 2026-10-07

CVE-2026-104414

CVE-2026-104414 is a stored XSS vulnerability in Ghost, a popular open-source blogging platform. The vulnerability allows an attacker to inject malicious scripts into post content via oEmbed photo responses, potentially leading to admin session compromise. The vulnerability affects Ghost versions from 2.1.0 up to 6.64.0. A fix is available in version 6.64.0.

HIGH TryGhost CVE published 2026-10-07

CVE-2026-104413

CVE-2026-104413: Ghost Stored XSS via Bookmark Card Images allows any staff user, including Contributors, to host arbitrary HTML on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is present in Ghost from v5.94.0 up to v6.64.0 and is fixed in v6.64.0. The vulnerability allows for potential compromise of admin sessions and hosting of arbitrary HTML. Defe [truncated]

LOW TryGhost CVE published 2026-10-07

CVE-2026-104415

CVE-2026-104415 debrief based on the supplied source corpus. The CVE record was published on 2026-10-07T20:27:22.000Z and has not been modified since then. The vulnerability allows staff-level users to determine the relative ordering of other staff users' hashed passwords in the Ghost Admin API. This does not directly disclose password hashes and does not provide a practical path to recovering a password. [truncated]

HIGH TryGhost CVE published 2026-10-07

CVE-2026-104416

CVE-2026-104416 debrief based on the supplied source corpus. The CVE record was published on 2026-10-07T20:26:19.000Z and has not been modified since then. This vulnerability affects Ghost installations, particularly those with staff users and invite functionality, allowing potential privilege escalation. Defenders should assess exposure and prioritize updates to mitigate risks. The CVE details a scenario [truncated]

MEDIUM TryGhost CVE published 2026-10-07

CVE-2026-104417

A vulnerability in Ghost's theme translation file loading allowed an authenticated Administrator to read JSON files outside the active theme's directory, potentially exposing server configuration secrets. This issue affects Ghost versions from 1.20.0 up to 6.64.0. An update to version 6.64.0 or later is recommended. The vulnerability was responsibly disclosed, and defenders should prioritize updating Ghos [truncated]

HIGH TryGhost CVE published 2026-10-07

CVE-2026-104418

CVE-2026-104418 is a remote code execution vulnerability in Ghost, a popular open-source blogging platform, affecting versions from 6.10.3 up to 6.64.0. An authenticated administrator can exploit this vulnerability via crafted theme translation files. The issue was responsibly disclosed by Miguel Segovia Gil of KPMG, Alemmi, and Tomer-PL. A fix is available in version 6.64.0.

MEDIUM TryGhost CVE published 2026-10-07

CVE-2026-104412

CVE-2026-104412 is a role escalation vulnerability in Ghost, a blogging platform, where editors could promote staff users to their own role. The issue existed from version 0.5.0 up to version 6.64.0 and was fixed in version 6.64.0. This vulnerability allows staff users with Editor or Super Editor roles to assign their own role to Author and Contributor users, potentially leading to unauthorized access. De [truncated]

HIGH TryGhost CVE published 2026-10-07

CVE-2026-104411

CVE-2026-104411 debrief based on the supplied source corpus. The CVE record was published on 2026-10-07T20:25:58.000Z and has not been modified since then. Defenders responsible for Ghost installations, particularly those using the default local storage adapter, should assess exposure and prioritize updating to version 6.64.0 or later. The vulnerability is present in Ghost from v6.22.1 up to v6.64.0. A st [truncated]

MEDIUM TryGhost CVE published 2026-10-07

CVE-2026-105680

CVE-2026-105680 debrief: A vulnerability in Ghost allows Author role users to delete posts and pages they did not author. This issue exists from version 5.81.0 up to 6.60.0. Users should update to version 6.60.0. System administrators and Ghost users with the Author role should assess exposure and prioritize updating vulnerable instances. This vulnerability allows unauthorized deletion of posts and pages, [truncated]

HIGH TryGhost CVE published 2026-10-07

CVE-2026-103289

CVE-2026-103289: Ghost Authorization Bypass Vulnerability. An input validation issue in the comments feature of Ghost versions between 5.9.0 and 6.44.1 allows members to access comments they are not authorized to access. Defenders should assess exposure and prioritize updates to version 6.44.1 or later. This vulnerability could lead to potential unauthorized access to comments, impacting member access con [truncated]

MEDIUM TryGhost CVE published 2026-10-07

CVE-2026-103287

A Server-Side Request Forgery (SSRF) vulnerability was found in the webhooks feature of Ghost, allowing staff users to probe internal hosts from the Ghost server. The vulnerability affects Ghost versions from 1.18.0 up to 6.27.0. A fix is available in version 6.27.0. This SSRF vulnerability allows staff users to probe internal hosts, potentially leading to unauthorized internal host discovery. Defenders s [truncated]

MEDIUM TryGhost CVE published 2026-10-07

CVE-2026-103290

CVE-2026-103290 is a path traversal vulnerability in Ghost ImageSize Service that may allow staff users to access local files outside intended data storage directories. The vulnerability affects Ghost versions from 6.14.0 to 6.27.0 and is fixed in version 6.27.0. Defenders responsible for Ghost installations, particularly those using versions between 6.14.0 and 6.27.0, should assess exposure and prioritiz [truncated]

MEDIUM TryGhost CVE published 2026-10-05

CVE-2026-105678

CVE-2026-105678 debrief: In Ghost content management system versions 0.5.0 through 6.64.0, staff users with Editor or Super Editor roles could promote Author and Contributor users to their own role, despite lacking permission to assign that role. This issue was fixed in version 6.64.0. The vulnerability allowed unauthorized role assignments, potentially leading to security risks. Defenders should assess e [truncated]

HIGH TryGhost CVE published 2026-10-05

CVE-2026-105651

CVE-2026-105651 is a high-severity vulnerability in Ghost, a Node.js content management system. From version 5.94.0 to 6.64.0, Ghost allowed staff users to store non-image files as bookmark icons or thumbnails, potentially leading to stored XSS attacks. This issue is fixed in version 6.64.0. The vulnerability allows staff users, including Contributors, to host arbitrary HTML on the site's domain, possibly [truncated]

MEDIUM TryGhost CVE published 2026-08-04

CVE-2026-70594

CVE-2026-70594 debrief based on CVE Program and NIST NVD records. Ghost Admin session fixation issue fixed in version 6.54.1. This vulnerability allowed potential session fixation attacks if not patched. Defenders should assess exposure and apply the patch to prevent potential attacks. The issue was fixed in version 6.54.1, which addresses the session fixation vulnerability in Ghost Admin. Successful expl [truncated]

MEDIUM TryGhost CVE published 2026-08-04

CVE-2026-70593

CVE-2026-70593 is a vulnerability in Ghost custom themes that allows staff users to write files outside the uploads directory via path traversal in LocalStorageBase and theme storage name handling. This issue is fixed in version 6.54.1. The vulnerability has a CVSS score of 6.6 and a severity of MEDIUM. Affected users should verify and restrict custom theme upload paths to prevent potential path traversal [truncated]

MEDIUM TryGhost CVE published 2026-08-04

CVE-2026-70592

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T22:17:17.140Z and has not been modified since then. CVE-2026-70592 is a MEDIUM-rated vulnerability in the Ghost Node.js content management system, allowing an Administrator-level user to remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity [truncated]

MEDIUM TryGhost CVE published 2026-08-04

CVE-2026-70591

CVE-2026-70591 is a Server-Side Request Forgery (SSRF) vulnerability in Ghost Admin image fetching, affecting Ghost versions from 0.10.0 to 6.54.1. This issue allows any staff-level user to perform a blind HTTP GET request against internal hosts, potentially probing open ports. The vulnerability is fixed in version 6.54.1. Defenders should prioritize verifying exposure of internal hosts and upgrading to G [truncated]

MEDIUM TryGhost CVE published 2026-08-04

CVE-2026-70590

CVE-2026-70590 debrief based on CVE Program and NIST NVD records. A Ghost content management system vulnerability allowed staff-level users to leak hashed passwords of other staff users via the Ghost Admin API prior to version 6.54.1. An offline password-guessing attack could lead to account takeover if successful. Device Verification should prevent login with a recovered password. The issue is fixed in v [truncated]

MEDIUM TryGhost CVE published 2026-08-04

CVE-2026-70588

CVE-2026-70588 is a medium-severity vulnerability affecting Ghost, a Node.js content management system. The Universal Import feature in Ghost Admin failed to properly sanitize imported content, resulting in cross-site scripting (XSS) in post content. This issue was fixed in version 6.54.1. Affected product deployments should be identified in managed environments, and owners should be assigned for follow-u [truncated]

MEDIUM TryGhost CVE published 2026-07-31

CVE-2026-25552

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T19:17:08.663Z and has not been modified since then. The IP spoofing vulnerability in Ghost CLI before 1.30.1 allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. This vulnerability can be e [truncated]

MEDIUM TryGhost CVE published 2026-07-09

CVE-2026-59817

CVE-2026-59817 is a vulnerability in Ghost's public donation checkout flow. An unauthenticated attacker could control donation checkout metadata and obtain full paid gift memberships for a minimal payment. This issue was fixed in version 6.44.0. Sites using Ghost versions before 6.44.0 should prioritize patching to prevent potential unauthorized access to paid gift memberships. The vulnerability has a CVS [truncated]