Known Vulnerabilities for Ghost by TryGhost
Listed below are 10 of the newest known vulnerabilities associated with "Ghost" by "TryGhost".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-89511 json | In the Linux kernel, the following vulnerability has been resolved: qede: Fix NULL pointer dereference in TPA fragment proce... | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-81806 json | Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This is... | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-80979 json | In the Linux kernel, the following vulnerability has been resolved: net/smc: unregister the connection before draining the r... | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-72596 json | A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts ow... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-70596 json | Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to cr... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-70595 json | Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such a... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-70594 json | Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on lo... | Not Provided | 2026-08-04 | 2026-08-05 |
| CVE-2026-70593 json | Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user... | Not Provided | 2026-08-04 | 2026-08-05 |
| CVE-2026-70592 json | Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite ... | Not Provided | 2026-08-04 | 2026-08-05 |
| CVE-2026-70591 json | Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fe... | Not Provided | 2026-08-04 | 2026-08-05 |