Technology · npm
ghost (npm) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 39 vulnerabilities in ghost (npm): 0 in the last 7 days and 10 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-70596, was published on 5 August 2026.
- Last 7 days
- 0
- Last 90 days
- 10
- Critical, all time
- 2
- Exploited in the wild
- 0
About ghost (npm)
Ghost is a professional publishing platform built on a Node.js stack for creating and managing online content.
Latest ghost (npm) vulnerabilities
- CVE-2026-70596: Ghost stored XSS in feature image captionsmediumCVSS 4.3EPSS 0.3%
- CVE-2026-70595: Ghost SSRF in Webmentions functionalitymediumCVSS 4EPSS 0.3%
- CVE-2026-70594: Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on…mediumCVSS 6.7EPSS 0.2%
- CVE-2026-70593: Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff…mediumCVSS 6.6EPSS 0.4%
- CVE-2026-70592: Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely…mediumCVSS 5.5EPSS 0.4%
- CVE-2026-70591: Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image…mediumCVSS 4.1EPSS 0.4%
- CVE-2026-70590: Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords…mediumCVSS 4.8EPSS 0.3%
- CVE-2026-70589: Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem…mediumCVSS 4.8EPSS 0.3%
- CVE-2026-70588: Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed…mediumCVSS 5EPSS 0.4%
- CVE-2026-59817: TryGhost Ghost authorization bypass in donation checkout flowmediumCVSS 5.3EPSS 0.4%
- CVE-2026-53949: TryGhost Ghost information disclosure via Content API filter bypassmediumCVSS 5.3EPSS 0.4%
- CVE-2026-53948: TryGhost Ghost stored XSS via Content-Type spoofing in Admin APImediumCVSS 5.4EPSS 0.2%
- CVE-2026-53947: TryGhost Ghost information disclosure in members signin endpointmediumCVSS 5.3EPSS 0.4%
- CVE-2026-53946: TryGhost Ghost SSRF in image-size fetchmediumCVSS 5.4EPSS 0.2%
- CVE-2026-53945: TryGhost Ghost SSRF bypass via DNS rebindingmediumCVSS 4EPSS 0.2%
- CVE-2026-53944: TryGhost Ghost SSRF via IPv6 private IP filter bypassmediumCVSS 5.8EPSS 0.3%
- CVE-2026-53943: TryGhost Ghost cache poisoning in frontend via x-ghost-preview headercriticalCVSS 9.6EPSS 0.4%
- CVE-2026-29784: Ghost incomplete CSRF protections in OTC loginlowCVSS 3.1EPSS 0.2%
- CVE-2026-29053: Ghost Remote Code Execution via Malicious ThemeslowCVSS 3.1EPSS 4.8%
- CVE-2026-26980: Ghost CMS SQL injection in Content APIcriticalCVSS 9.4EPSS 5.0%
- CVE-2026-24778: Ghost XSS via malicious Portal preview linkslowCVSS 3.1EPSS 0.3%
- CVE-2026-22596: Ghost SQL injection in Members Activity FeedlowCVSS 3.1EPSS 0.5%
- CVE-2026-22595: Ghost Staff Token permission bypasslowCVSS 3.1EPSS 0.5%
- CVE-2026-22594: Ghost staff 2FA bypasslowCVSS 3.1EPSS 1.3%
- CVE-2025-9862: Ghost Server Side Request Forgery in oEmbed BookmarkmediumCVSS 4EPSS 0.5%
Most severe ghost (npm) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-53943: TryGhost Ghost cache poisoning in frontend via x-ghost-preview headercriticalCVSS 9.6EPSS 0.4%
- CVE-2026-26980: Ghost CMS SQL injection in Content APIcriticalCVSS 9.4EPSS 5.0%
- CVE-2026-70594: Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on…mediumCVSS 6.7EPSS 0.2%
- CVE-2026-70593: Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff…mediumCVSS 6.6EPSS 0.4%
- CVE-2026-53944: TryGhost Ghost SSRF via IPv6 private IP filter bypassmediumCVSS 5.8EPSS 0.3%
- CVE-2026-70592: Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely…mediumCVSS 5.5EPSS 0.4%
- CVE-2026-53948: TryGhost Ghost stored XSS via Content-Type spoofing in Admin APImediumCVSS 5.4EPSS 0.2%
- CVE-2026-53946: TryGhost Ghost SSRF in image-size fetchmediumCVSS 5.4EPSS 0.2%
- CVE-2026-59817: TryGhost Ghost authorization bypass in donation checkout flowmediumCVSS 5.3EPSS 0.4%
- CVE-2026-53949: TryGhost Ghost information disclosure via Content API filter bypassmediumCVSS 5.3EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 9 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/ghost.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "ghost (npm) vulnerabilities", https://junglewise.ai/threats/technologies/ghost, 28 September 2026.