High severity7.3NVD Advisory· Published Oct 2, 2026
CVE-2026-104413
CVE-2026-104413
Description
Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to host arbitrary HTML by abusing bookmark card image fetching. Attackers can create bookmark cards that store non-image files from external websites as icons or thumbnails to compromise other staff users' admin sessions.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.