PatchSiren

TryGhost CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM TryGhost CVE published 2026-08-04

CVE-2026-70594

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T22:17:17.423Z and has not been modified since then. CVE-2026-70594 is a session fixation vulnerability in Ghost Admin, a Node.js content management system, affecting versions from 2.2.0 to 6.54.1. Successful exploitation requires another vulnerability on the same domain. The issue is fixed in ver [truncated]

MEDIUM TryGhost CVE published 2026-08-04

CVE-2026-70593

CVE-2026-70593 is a vulnerability in Ghost custom themes that allows staff users to write files outside the uploads directory via path traversal in LocalStorageBase and theme storage name handling. This issue is fixed in version 6.54.1. The vulnerability has a CVSS score of 6.6 and a severity of MEDIUM. Affected users should verify and restrict custom theme upload paths to prevent potential path traversal [truncated]

MEDIUM TryGhost CVE published 2026-08-04

CVE-2026-70592

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T22:17:17.140Z and has not been modified since then. CVE-2026-70592 is a MEDIUM-rated vulnerability in the Ghost Node.js content management system, allowing an Administrator-level user to remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity [truncated]

MEDIUM TryGhost CVE published 2026-08-04

CVE-2026-70591

CVE-2026-70591 is a Server-Side Request Forgery vulnerability in Ghost Admin image fetching, affecting Ghost versions from 0.10.0 to 6.54.0. Staff-level users can perform blind HTTP GET requests against internal hosts. The issue is fixed in version 6.54.1. Users should review their installations and update to the fixed version. This vulnerability could be used to probe open ports on internal hosts, althou [truncated]

MEDIUM TryGhost CVE published 2026-08-04

CVE-2026-70590

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T22:17:16.850Z and has not been modified since then. CVE-2026-70590 is a medium-severity vulnerability in Ghost, a Node.js content management system. Staff-level users could leak hashed passwords of other staff users through the Ghost Admin API, potentially leading to account takeover if an offlin [truncated]

MEDIUM TryGhost CVE published 2026-08-04

CVE-2026-70588

The CVE-2026-70588 vulnerability affects the Ghost content management system, specifically versions 5.26.0 through 6.54.0. This vulnerability is classified as a cross-site scripting (XSS) issue due to improper sanitization of imported content in the Universal Import feature of Ghost Admin. The likely operational impact includes unauthorized actions or data breaches resulting from the injection of maliciou [truncated]

MEDIUM TryGhost CVE published 2026-07-31

CVE-2026-25552

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T19:17:08.663Z and has not been modified since then. The IP spoofing vulnerability in Ghost CLI before 1.30.1 allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. This vulnerability can be e [truncated]

MEDIUM TryGhost CVE published 2026-07-09

CVE-2026-59817

CVE-2026-59817 is a vulnerability in Ghost's public donation checkout flow. An unauthenticated attacker could control donation checkout metadata and obtain full paid gift memberships for a minimal payment. This issue was fixed in version 6.44.0. Sites using Ghost versions before 6.44.0 should prioritize patching to prevent potential unauthorized access to paid gift memberships. The vulnerability has a CVS [truncated]

CRITICAL TryGhost CVE published 2026-02-20

CVE-2026-26980

Ghost CMS versions 3.24.0 through 6.19.0 contain a critical unauthenticated SQL injection vulnerability allowing arbitrary database reads. The flaw enables remote attackers to extract sensitive data without authentication. Ghost Foundation patched this in version 6.19.1 released February 2026. Organizations should upgrade immediately and audit database access logs for anomalous queries.