VYPR

Vendor CVEs

Tryghost

All CVEs

55 total · sorted by risk
  • CVE-2026-70596MedAug 5, 2026
    risk 0.21cvss 4.3epss 0.00

    Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin session, resulting in privilege…

  • CVE-2026-70591MedAug 4, 2026
    risk 0.20cvss 4.1epss 0.00

    Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to…

  • CVE-2026-53945MedJun 24, 2026
    risk 0.19cvss 4.0epss 0.00

    Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue…

  • CVE-2026-25552LowJul 31, 2026
    risk 0.17cvss 3.7epss 0.00

    Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers can append attacker-controlled values to…

  • CVE-2026-22597LowJan 10, 2026
    risk 0.11cvss 2.7epss 0.00

    Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost’s media inliner mechanism allows staff users in possession of a valid authentication token for the Ghost Admin API to exfiltrate data from…

Page 2 of 2