{"schema_version":1,"title":"ghost (npm) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 39 vulnerabilities in ghost (npm): 0 in the last 7 days and 10 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-70596, was published on 5 August 2026.","url":"https://junglewise.ai/threats/technologies/ghost","json_url":"https://junglewise.ai/threats/technologies/ghost.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/ghost","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":39,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":10,"last_365_days":24},"latest":[{"cve":"CVE-2026-70596","cvss":4.3,"epss":0.0032,"slug":"cve-2026-70596-ghost-stored-xss-in-feature-image-captions","title":"Ghost stored XSS in feature image captions","severity":"medium","exploited":false,"published_at":"2026-08-05T14:40:15+00:00","url":"https://junglewise.ai/threats/cve-2026-70596-ghost-stored-xss-in-feature-image-captions"},{"cve":"CVE-2026-70595","cvss":4,"epss":0.0028,"slug":"cve-2026-70595-ghost-ssrf-in-webmentions-functionality","title":"Ghost SSRF in Webmentions functionality","severity":"medium","exploited":false,"published_at":"2026-08-05T14:37:14+00:00","url":"https://junglewise.ai/threats/cve-2026-70595-ghost-ssrf-in-webmentions-functionality"},{"cve":"CVE-2026-70594","cvss":6.7,"epss":0.0024,"slug":"cve-2026-70594-tryghost-ghost-session-fixation-in-ghost-admin","title":"Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could","severity":"medium","exploited":false,"published_at":"2026-08-04T22:17:17.423+00:00","url":"https://junglewise.ai/threats/cve-2026-70594-tryghost-ghost-session-fixation-in-ghost-admin"},{"cve":"CVE-2026-70593","cvss":6.6,"epss":0.0041,"slug":"cve-2026-70593-ghost-path-traversal-in-custom-theme-upload","title":"Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files","severity":"medium","exploited":false,"published_at":"2026-08-04T22:17:17.29+00:00","url":"https://junglewise.ai/threats/cve-2026-70593-ghost-path-traversal-in-custom-theme-upload"},{"cve":"CVE-2026-70592","cvss":5.5,"epss":0.0044,"slug":"cve-2026-70592-ghost-path-traversal-in-database-backup-functionality","title":"Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files o","severity":"medium","exploited":false,"published_at":"2026-08-04T22:17:17.14+00:00","url":"https://junglewise.ai/threats/cve-2026-70592-ghost-path-traversal-in-database-backup-functionality"},{"cve":"CVE-2026-70591","cvss":4.1,"epss":0.0037,"slug":"cve-2026-70591-ghost-ssrf-in-ghost-admin-image-fetching","title":"Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed","severity":"medium","exploited":false,"published_at":"2026-08-04T22:17:16.997+00:00","url":"https://junglewise.ai/threats/cve-2026-70591-ghost-ssrf-in-ghost-admin-image-fetching"},{"cve":"CVE-2026-70590","cvss":4.8,"epss":0.0032,"slug":"cve-2026-70590-tryghost-ghost-password-hash-disclosure-in-admin-api","title":"Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff use","severity":"medium","exploited":false,"published_at":"2026-08-04T22:17:16.85+00:00","url":"https://junglewise.ai/threats/cve-2026-70590-tryghost-ghost-password-hash-disclosure-in-admin-api"},{"cve":"CVE-2026-70589","cvss":4.8,"epss":0.0027,"slug":"cve-2026-70589-ghost-improper-validation-of-archived-subscription-offers","title":"Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offe","severity":"medium","exploited":false,"published_at":"2026-08-04T22:17:16.707+00:00","url":"https://junglewise.ai/threats/cve-2026-70589-ghost-improper-validation-of-archived-subscription-offers"},{"cve":"CVE-2026-70588","cvss":5,"epss":0.0043,"slug":"cve-2026-70588-ghost-xss-in-universal-import-feature","title":"Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanit","severity":"medium","exploited":false,"published_at":"2026-08-04T21:16:38.75+00:00","url":"https://junglewise.ai/threats/cve-2026-70588-ghost-xss-in-universal-import-feature"},{"cve":"CVE-2026-59817","cvss":5.3,"epss":0.004,"slug":"cve-2026-59817-tryghost-ghost-authorization-bypass-in-donation-checkout-flow","title":"TryGhost Ghost authorization bypass in donation checkout flow","severity":"medium","exploited":false,"published_at":"2026-07-09T18:16:57.603+00:00","url":"https://junglewise.ai/threats/cve-2026-59817-tryghost-ghost-authorization-bypass-in-donation-checkout-flow"},{"cve":"CVE-2026-53949","cvss":5.3,"epss":0.0036,"slug":"cve-2026-53949-tryghost-ghost-information-disclosure-via-content-api-filter","title":"TryGhost Ghost information disclosure via Content API filter bypass","severity":"medium","exploited":false,"published_at":"2026-06-24T19:17:12.58+00:00","url":"https://junglewise.ai/threats/cve-2026-53949-tryghost-ghost-information-disclosure-via-content-api-filter"},{"cve":"CVE-2026-53948","cvss":5.4,"epss":0.0023,"slug":"cve-2026-53948-tryghost-ghost-stored-xss-via-content-type-spoofing-in-admin-api","title":"TryGhost Ghost stored XSS via Content-Type spoofing in Admin API","severity":"medium","exploited":false,"published_at":"2026-06-24T19:17:12.46+00:00","url":"https://junglewise.ai/threats/cve-2026-53948-tryghost-ghost-stored-xss-via-content-type-spoofing-in-admin-api"},{"cve":"CVE-2026-53947","cvss":5.3,"epss":0.0035,"slug":"cve-2026-53947-tryghost-ghost-information-disclosure-in-members-signin-endpoint","title":"TryGhost Ghost information disclosure in members signin endpoint","severity":"medium","exploited":false,"published_at":"2026-06-24T19:17:12.337+00:00","url":"https://junglewise.ai/threats/cve-2026-53947-tryghost-ghost-information-disclosure-in-members-signin-endpoint"},{"cve":"CVE-2026-53946","cvss":5.4,"epss":0.0021,"slug":"cve-2026-53946-tryghost-ghost-ssrf-in-image-size-fetch","title":"TryGhost Ghost SSRF in image-size fetch","severity":"medium","exploited":false,"published_at":"2026-06-24T19:17:12.217+00:00","url":"https://junglewise.ai/threats/cve-2026-53946-tryghost-ghost-ssrf-in-image-size-fetch"},{"cve":"CVE-2026-53945","cvss":4,"epss":0.0021,"slug":"cve-2026-53945-tryghost-ghost-ssrf-bypass-via-dns-rebinding","title":"TryGhost Ghost SSRF bypass via DNS rebinding","severity":"medium","exploited":false,"published_at":"2026-06-24T19:17:12.09+00:00","url":"https://junglewise.ai/threats/cve-2026-53945-tryghost-ghost-ssrf-bypass-via-dns-rebinding"},{"cve":"CVE-2026-53944","cvss":5.8,"epss":0.0033,"slug":"cve-2026-53944-tryghost-ghost-ssrf-via-ipv6-private-ip-filter-bypass","title":"TryGhost Ghost SSRF via IPv6 private IP filter bypass","severity":"medium","exploited":false,"published_at":"2026-06-24T19:17:11.957+00:00","url":"https://junglewise.ai/threats/cve-2026-53944-tryghost-ghost-ssrf-via-ipv6-private-ip-filter-bypass"},{"cve":"CVE-2026-53943","cvss":9.6,"epss":0.0045,"slug":"cve-2026-53943-tryghost-ghost-cache-poisoning-in-frontend-via-x-ghost-preview","title":"TryGhost Ghost cache poisoning in frontend via x-ghost-preview header","severity":"critical","exploited":false,"published_at":"2026-06-24T19:17:11.82+00:00","url":"https://junglewise.ai/threats/cve-2026-53943-tryghost-ghost-cache-poisoning-in-frontend-via-x-ghost-preview"},{"cve":"CVE-2026-29784","cvss":3.1,"epss":0.0019,"slug":"cve-2026-29784-ghost-incomplete-csrf-protections-in-otc-login","title":"Ghost incomplete CSRF protections in OTC login","severity":"low","exploited":false,"published_at":"2026-03-05T00:42:55+00:00","url":"https://junglewise.ai/threats/cve-2026-29784-ghost-incomplete-csrf-protections-in-otc-login"},{"cve":"CVE-2026-29053","cvss":3.1,"epss":0.048,"slug":"cve-2026-29053-ghost-remote-code-execution-via-malicious-themes","title":"Ghost Remote Code Execution via Malicious Themes","severity":"low","exploited":false,"published_at":"2026-03-03T20:01:21+00:00","url":"https://junglewise.ai/threats/cve-2026-29053-ghost-remote-code-execution-via-malicious-themes"},{"cve":"CVE-2026-26980","cvss":9.4,"epss":0.0495,"slug":"cve-2026-26980-ghost-cms-sql-injection-in-content-api","title":"Ghost CMS SQL injection in Content API","severity":"critical","exploited":false,"published_at":"2026-02-20T02:16:54.213+00:00","url":"https://junglewise.ai/threats/cve-2026-26980-ghost-cms-sql-injection-in-content-api"},{"cve":"CVE-2026-24778","cvss":3.1,"epss":0.0029,"slug":"cve-2026-24778-ghost-xss-via-malicious-portal-preview-links","title":"Ghost XSS via malicious Portal preview links","severity":"low","exploited":false,"published_at":"2026-01-28T16:11:59+00:00","url":"https://junglewise.ai/threats/cve-2026-24778-ghost-xss-via-malicious-portal-preview-links"},{"cve":"CVE-2026-22596","cvss":3.1,"epss":0.0047,"slug":"cve-2026-22596-ghost-sql-injection-in-members-activity-feed","title":"Ghost SQL injection in Members Activity Feed","severity":"low","exploited":false,"published_at":"2026-01-08T21:36:37+00:00","url":"https://junglewise.ai/threats/cve-2026-22596-ghost-sql-injection-in-members-activity-feed"},{"cve":"CVE-2026-22595","cvss":3.1,"epss":0.0055,"slug":"cve-2026-22595-ghost-staff-token-permission-bypass","title":"Ghost Staff Token permission bypass","severity":"low","exploited":false,"published_at":"2026-01-08T21:32:53+00:00","url":"https://junglewise.ai/threats/cve-2026-22595-ghost-staff-token-permission-bypass"},{"cve":"CVE-2026-22594","cvss":3.1,"epss":0.0132,"slug":"cve-2026-22594-ghost-staff-2fa-bypass","title":"Ghost staff 2FA bypass","severity":"low","exploited":false,"published_at":"2026-01-08T21:29:47+00:00","url":"https://junglewise.ai/threats/cve-2026-22594-ghost-staff-2fa-bypass"},{"cve":"CVE-2025-9862","cvss":4,"epss":0.0052,"slug":"cve-2025-9862-ghost-server-side-request-forgery-in-oembed-bookmark","title":"Ghost Server Side Request Forgery in oEmbed Bookmark","severity":"medium","exploited":false,"published_at":"2025-09-15T20:31:14+00:00","url":"https://junglewise.ai/threats/cve-2025-9862-ghost-server-side-request-forgery-in-oembed-bookmark"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"flowise (npm)","slug":"flowise","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/flowise"},{"name":"vm2 (npm)","slug":"vm2","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/vm2"},{"name":"@budibase/server (npm)","slug":"budibase-server","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/budibase-server"},{"name":"directus (npm)","slug":"directus","vulnerabilities":60,"url":"https://junglewise.ai/threats/technologies/directus"},{"name":"nocodb (npm)","slug":"nocodb","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/nocodb"},{"name":"hono (npm)","slug":"hono","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/hono"},{"name":"parse-server (npm)","slug":"parse-server","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/parse-server"},{"name":"dompurify (npm)","slug":"dompurify","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/dompurify"},{"name":"flowise-components (npm)","slug":"flowise-components","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/flowise-components"},{"name":"astro (npm)","slug":"astro","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/astro"},{"name":"@anthropic-ai/claude-code (npm)","slug":"anthropic-ai-claude-code","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/anthropic-ai-claude-code"},{"name":"9router (npm)","slug":"9router","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/9router"}],"technology":{"hub":true,"name":"ghost (npm)","slug":"ghost","vendor":{"name":"npm","slug":"npm","url":"https://junglewise.ai/threats/vendors/npm"},"aliases":[],"homepage":"https://ghost.org/","repo_url":"https://github.com/TryGhost/Ghost","description":"Ghost is a professional publishing platform built on a Node.js stack for creating and managing online content.","url":"https://junglewise.ai/threats/technologies/ghost"},"most_severe":[{"cve":"CVE-2026-53943","cvss":9.6,"epss":0.0045,"slug":"cve-2026-53943-tryghost-ghost-cache-poisoning-in-frontend-via-x-ghost-preview","title":"TryGhost Ghost cache poisoning in frontend via x-ghost-preview header","severity":"critical","exploited":false,"published_at":"2026-06-24T19:17:11.82+00:00","url":"https://junglewise.ai/threats/cve-2026-53943-tryghost-ghost-cache-poisoning-in-frontend-via-x-ghost-preview"},{"cve":"CVE-2026-26980","cvss":9.4,"epss":0.0495,"slug":"cve-2026-26980-ghost-cms-sql-injection-in-content-api","title":"Ghost CMS SQL injection in Content API","severity":"critical","exploited":false,"published_at":"2026-02-20T02:16:54.213+00:00","url":"https://junglewise.ai/threats/cve-2026-26980-ghost-cms-sql-injection-in-content-api"},{"cve":"CVE-2026-70594","cvss":6.7,"epss":0.0024,"slug":"cve-2026-70594-tryghost-ghost-session-fixation-in-ghost-admin","title":"Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could","severity":"medium","exploited":false,"published_at":"2026-08-04T22:17:17.423+00:00","url":"https://junglewise.ai/threats/cve-2026-70594-tryghost-ghost-session-fixation-in-ghost-admin"},{"cve":"CVE-2026-70593","cvss":6.6,"epss":0.0041,"slug":"cve-2026-70593-ghost-path-traversal-in-custom-theme-upload","title":"Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files","severity":"medium","exploited":false,"published_at":"2026-08-04T22:17:17.29+00:00","url":"https://junglewise.ai/threats/cve-2026-70593-ghost-path-traversal-in-custom-theme-upload"},{"cve":"CVE-2026-53944","cvss":5.8,"epss":0.0033,"slug":"cve-2026-53944-tryghost-ghost-ssrf-via-ipv6-private-ip-filter-bypass","title":"TryGhost Ghost SSRF via IPv6 private IP filter bypass","severity":"medium","exploited":false,"published_at":"2026-06-24T19:17:11.957+00:00","url":"https://junglewise.ai/threats/cve-2026-53944-tryghost-ghost-ssrf-via-ipv6-private-ip-filter-bypass"},{"cve":"CVE-2026-70592","cvss":5.5,"epss":0.0044,"slug":"cve-2026-70592-ghost-path-traversal-in-database-backup-functionality","title":"Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files o","severity":"medium","exploited":false,"published_at":"2026-08-04T22:17:17.14+00:00","url":"https://junglewise.ai/threats/cve-2026-70592-ghost-path-traversal-in-database-backup-functionality"},{"cve":"CVE-2026-53948","cvss":5.4,"epss":0.0023,"slug":"cve-2026-53948-tryghost-ghost-stored-xss-via-content-type-spoofing-in-admin-api","title":"TryGhost Ghost stored XSS via Content-Type spoofing in Admin API","severity":"medium","exploited":false,"published_at":"2026-06-24T19:17:12.46+00:00","url":"https://junglewise.ai/threats/cve-2026-53948-tryghost-ghost-stored-xss-via-content-type-spoofing-in-admin-api"},{"cve":"CVE-2026-53946","cvss":5.4,"epss":0.0021,"slug":"cve-2026-53946-tryghost-ghost-ssrf-in-image-size-fetch","title":"TryGhost Ghost SSRF in image-size fetch","severity":"medium","exploited":false,"published_at":"2026-06-24T19:17:12.217+00:00","url":"https://junglewise.ai/threats/cve-2026-53946-tryghost-ghost-ssrf-in-image-size-fetch"},{"cve":"CVE-2026-59817","cvss":5.3,"epss":0.004,"slug":"cve-2026-59817-tryghost-ghost-authorization-bypass-in-donation-checkout-flow","title":"TryGhost Ghost authorization bypass in donation checkout flow","severity":"medium","exploited":false,"published_at":"2026-07-09T18:16:57.603+00:00","url":"https://junglewise.ai/threats/cve-2026-59817-tryghost-ghost-authorization-bypass-in-donation-checkout-flow"},{"cve":"CVE-2026-53949","cvss":5.3,"epss":0.0036,"slug":"cve-2026-53949-tryghost-ghost-information-disclosure-via-content-api-filter","title":"TryGhost Ghost information disclosure via Content API filter bypass","severity":"medium","exploited":false,"published_at":"2026-06-24T19:17:12.58+00:00","url":"https://junglewise.ai/threats/cve-2026-53949-tryghost-ghost-information-disclosure-via-content-api-filter"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}