{"schema_version":1,"title":"Ghost vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 18 vulnerabilities in Ghost: 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-70589, was published on 4 August 2026.","url":"https://junglewise.ai/threats/vendors/ghost","json_url":"https://junglewise.ai/threats/vendors/ghost.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/ghost","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":0,"all_time":18,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":6},"latest":[{"cve":"CVE-2026-70589","cvss":4.8,"epss":0.0027,"slug":"cve-2026-70589-ghost-improper-validation-of-archived-subscription-offers","title":"Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offe","severity":"medium","exploited":false,"published_at":"2026-08-04T22:17:16.707+00:00","url":"https://junglewise.ai/threats/cve-2026-70589-ghost-improper-validation-of-archived-subscription-offers"},{"cve":"CVE-2026-29784","cvss":3.1,"epss":0.0019,"slug":"cve-2026-29784-ghost-incomplete-csrf-protections-in-otc-login","title":"Ghost incomplete CSRF protections in OTC login","severity":"low","exploited":false,"published_at":"2026-03-05T00:42:55+00:00","url":"https://junglewise.ai/threats/cve-2026-29784-ghost-incomplete-csrf-protections-in-otc-login"},{"cve":"CVE-2026-24778","cvss":3.1,"epss":0.0029,"slug":"cve-2026-24778-ghost-xss-via-malicious-portal-preview-links","title":"Ghost XSS via malicious Portal preview links","severity":"low","exploited":false,"published_at":"2026-01-28T16:11:59+00:00","url":"https://junglewise.ai/threats/cve-2026-24778-ghost-xss-via-malicious-portal-preview-links"},{"cve":"CVE-2026-22596","cvss":3.1,"epss":0.0047,"slug":"cve-2026-22596-ghost-sql-injection-in-members-activity-feed","title":"Ghost SQL injection in Members Activity Feed","severity":"low","exploited":false,"published_at":"2026-01-08T21:36:37+00:00","url":"https://junglewise.ai/threats/cve-2026-22596-ghost-sql-injection-in-members-activity-feed"},{"cve":"CVE-2026-22595","cvss":3.1,"epss":0.0055,"slug":"cve-2026-22595-ghost-staff-token-permission-bypass","title":"Ghost Staff Token permission bypass","severity":"low","exploited":false,"published_at":"2026-01-08T21:32:53+00:00","url":"https://junglewise.ai/threats/cve-2026-22595-ghost-staff-token-permission-bypass"},{"cve":"CVE-2026-22594","cvss":3.1,"epss":0.0132,"slug":"cve-2026-22594-ghost-staff-2fa-bypass","title":"Ghost staff 2FA bypass","severity":"low","exploited":false,"published_at":"2026-01-08T21:29:47+00:00","url":"https://junglewise.ai/threats/cve-2026-22594-ghost-staff-2fa-bypass"},{"cve":"CVE-2025-9862","cvss":4,"epss":0.0052,"slug":"cve-2025-9862-ghost-server-side-request-forgery-in-oembed-bookmark","title":"Ghost Server Side Request Forgery in oEmbed Bookmark","severity":"medium","exploited":false,"published_at":"2025-09-15T20:31:14+00:00","url":"https://junglewise.ai/threats/cve-2025-9862-ghost-server-side-request-forgery-in-oembed-bookmark"},{"cve":"CVE-2024-43409","cvss":3.1,"epss":0.0033,"slug":"cve-2024-43409-ghost-improper-authentication-in-member-endpoints","title":"Ghost improper authentication in member endpoints","severity":"low","exploited":false,"published_at":"2024-08-20T20:04:49+00:00","url":"https://junglewise.ai/threats/cve-2024-43409-ghost-improper-authentication-in-member-endpoints"},{"cve":"CVE-2024-23724","cvss":3.1,"epss":0.0349,"slug":"cve-2024-23724-ghost-stored-cross-site-scripting-via-svg-profile-picture","title":"Ghost stored cross-site scripting via SVG profile picture","severity":"low","exploited":false,"published_at":"2024-02-11T03:30:17+00:00","url":"https://junglewise.ai/threats/cve-2024-23724-ghost-stored-cross-site-scripting-via-svg-profile-picture"},{"cve":"CVE-2024-23725","cvss":3.1,"epss":0.0044,"slug":"cve-2024-23725-ghost-cross-site-scripting-in-post-excerpts","title":"Ghost cross-site scripting in post excerpts","severity":"low","exploited":false,"published_at":"2024-01-21T06:30:22+00:00","url":"https://junglewise.ai/threats/cve-2024-23725-ghost-cross-site-scripting-in-post-excerpts"},{"cve":"CVE-2023-40028","cvss":3.1,"epss":0.6874,"slug":"cve-2023-40028-ghost-arbitrary-file-read-via-symlinks-in-content-import","title":"Ghost arbitrary file read via symlinks in content import","severity":"low","exploited":false,"published_at":"2023-08-15T20:35:20+00:00","url":"https://junglewise.ai/threats/cve-2023-40028-ghost-arbitrary-file-read-via-symlinks-in-content-import"},{"cve":"CVE-2022-41654","cvss":3.1,"epss":0.1891,"slug":"cve-2022-41654-ghost-unauthorized-newsletter-modification-via-improper-access","title":"Ghost unauthorized newsletter modification via improper access control","severity":"low","exploited":false,"published_at":"2022-11-28T22:06:24+00:00","url":"https://junglewise.ai/threats/cve-2022-41654-ghost-unauthorized-newsletter-modification-via-improper-access"},{"cvss":3.1,"slug":"ghost-remote-code-execution-in-locale-setting-change-736f6d52","title":"Ghost remote code execution in locale setting change","severity":"low","exploited":false,"published_at":"2022-06-17T01:16:03+00:00","url":"https://junglewise.ai/threats/ghost-remote-code-execution-in-locale-setting-change-736f6d52"},{"cve":"CVE-2022-27139","cvss":3.1,"epss":0.0405,"slug":"cve-2022-27139-ghost-arbitrary-file-upload-via-crafted-svg","title":"Ghost arbitrary file upload via crafted SVG","severity":"low","exploited":false,"published_at":"2022-04-13T00:00:24+00:00","url":"https://junglewise.ai/threats/cve-2022-27139-ghost-arbitrary-file-upload-via-crafted-svg"},{"cve":"CVE-2022-28397","cvss":3.1,"epss":0.035,"slug":"cve-2022-28397-ghost-arbitrary-file-upload","title":"Ghost arbitrary file upload","severity":"low","exploited":false,"published_at":"2022-04-13T00:00:22+00:00","url":"https://junglewise.ai/threats/cve-2022-28397-ghost-arbitrary-file-upload"},{"cve":"CVE-2021-39192","cvss":3.1,"epss":0.0102,"slug":"cve-2021-39192-ghost-privilege-escalation-in-integrations-api","title":"Ghost privilege escalation in integrations API","severity":"low","exploited":false,"published_at":"2021-07-22T19:43:16+00:00","url":"https://junglewise.ai/threats/cve-2021-39192-ghost-privilege-escalation-in-integrations-api"},{"cve":"CVE-2020-8134","cvss":3.1,"epss":0.0122,"slug":"cve-2020-8134-ghost-cms-server-side-request-forgery","title":"Ghost CMS server-side request forgery","severity":"low","exploited":false,"published_at":"2021-05-06T18:28:08+00:00","url":"https://junglewise.ai/threats/cve-2020-8134-ghost-cms-server-side-request-forgery"},{"cve":"CVE-2021-29484","cvss":3.1,"epss":0.0794,"slug":"cve-2021-29484-ghost-dom-xss-in-theme-preview-endpoint","title":"Ghost DOM XSS in theme preview endpoint","severity":"low","exploited":false,"published_at":"2021-04-29T21:53:18+00:00","url":"https://junglewise.ai/threats/cve-2021-29484-ghost-dom-xss-in-theme-preview-endpoint"}],"vendor":{"hub":true,"name":"Ghost","slug":"ghost","url":"https://junglewise.ai/threats/vendors/ghost"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-70589","cvss":4.8,"epss":0.0027,"slug":"cve-2026-70589-ghost-improper-validation-of-archived-subscription-offers","title":"Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offe","severity":"medium","exploited":false,"published_at":"2026-08-04T22:17:16.707+00:00","url":"https://junglewise.ai/threats/cve-2026-70589-ghost-improper-validation-of-archived-subscription-offers"},{"cve":"CVE-2025-9862","cvss":4,"epss":0.0052,"slug":"cve-2025-9862-ghost-server-side-request-forgery-in-oembed-bookmark","title":"Ghost Server Side Request Forgery in oEmbed Bookmark","severity":"medium","exploited":false,"published_at":"2025-09-15T20:31:14+00:00","url":"https://junglewise.ai/threats/cve-2025-9862-ghost-server-side-request-forgery-in-oembed-bookmark"},{"cve":"CVE-2023-40028","cvss":3.1,"epss":0.6874,"slug":"cve-2023-40028-ghost-arbitrary-file-read-via-symlinks-in-content-import","title":"Ghost arbitrary file read via symlinks in content import","severity":"low","exploited":false,"published_at":"2023-08-15T20:35:20+00:00","url":"https://junglewise.ai/threats/cve-2023-40028-ghost-arbitrary-file-read-via-symlinks-in-content-import"},{"cve":"CVE-2022-41654","cvss":3.1,"epss":0.1891,"slug":"cve-2022-41654-ghost-unauthorized-newsletter-modification-via-improper-access","title":"Ghost unauthorized newsletter modification via improper access control","severity":"low","exploited":false,"published_at":"2022-11-28T22:06:24+00:00","url":"https://junglewise.ai/threats/cve-2022-41654-ghost-unauthorized-newsletter-modification-via-improper-access"},{"cve":"CVE-2021-29484","cvss":3.1,"epss":0.0794,"slug":"cve-2021-29484-ghost-dom-xss-in-theme-preview-endpoint","title":"Ghost DOM XSS in theme preview endpoint","severity":"low","exploited":false,"published_at":"2021-04-29T21:53:18+00:00","url":"https://junglewise.ai/threats/cve-2021-29484-ghost-dom-xss-in-theme-preview-endpoint"},{"cve":"CVE-2022-27139","cvss":3.1,"epss":0.0405,"slug":"cve-2022-27139-ghost-arbitrary-file-upload-via-crafted-svg","title":"Ghost arbitrary file upload via crafted SVG","severity":"low","exploited":false,"published_at":"2022-04-13T00:00:24+00:00","url":"https://junglewise.ai/threats/cve-2022-27139-ghost-arbitrary-file-upload-via-crafted-svg"},{"cve":"CVE-2022-28397","cvss":3.1,"epss":0.035,"slug":"cve-2022-28397-ghost-arbitrary-file-upload","title":"Ghost arbitrary file upload","severity":"low","exploited":false,"published_at":"2022-04-13T00:00:22+00:00","url":"https://junglewise.ai/threats/cve-2022-28397-ghost-arbitrary-file-upload"},{"cve":"CVE-2024-23724","cvss":3.1,"epss":0.0349,"slug":"cve-2024-23724-ghost-stored-cross-site-scripting-via-svg-profile-picture","title":"Ghost stored cross-site scripting via SVG profile picture","severity":"low","exploited":false,"published_at":"2024-02-11T03:30:17+00:00","url":"https://junglewise.ai/threats/cve-2024-23724-ghost-stored-cross-site-scripting-via-svg-profile-picture"},{"cve":"CVE-2026-22594","cvss":3.1,"epss":0.0132,"slug":"cve-2026-22594-ghost-staff-2fa-bypass","title":"Ghost staff 2FA bypass","severity":"low","exploited":false,"published_at":"2026-01-08T21:29:47+00:00","url":"https://junglewise.ai/threats/cve-2026-22594-ghost-staff-2fa-bypass"},{"cve":"CVE-2020-8134","cvss":3.1,"epss":0.0122,"slug":"cve-2020-8134-ghost-cms-server-side-request-forgery","title":"Ghost CMS server-side request forgery","severity":"low","exploited":false,"published_at":"2021-05-06T18:28:08+00:00","url":"https://junglewise.ai/threats/cve-2020-8134-ghost-cms-server-side-request-forgery"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[]}