Known Vulnerabilities for Ghost by TryGhost
Listed below are 10 of the newest known vulnerabilities associated with "Ghost" by "TryGhost".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-53950 json | @tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerab... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-53949 json | Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API e... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-53948 json | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Conten... | Not Provided | 2026-06-24 | 2026-06-25 |
| CVE-2026-53947 json | Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members signin en... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-53946 json | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch missing ... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-53945 json | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests ... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-53944 json | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to byp... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-53943 json | Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-50221 json | In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, ... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-46656 json | Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remai... | Not Provided | 2026-06-08 | 2026-06-08 |