VYPR

Ghost Admin API

by Tryghost

CVEs (1)

  • CVE-2026-70590Aug 4, 2026
    risk 0.00cvss epss

    Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but…