CVEs we hold for Tryghost
Records whose assigning authority named Tryghost as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-70596Ghost: Cross-Site Scripting in Feature Image CaptionsTryGhost Ghost CVE-2026-70595Ghost: Server-Side Request Forgery Mitigation IssueTryGhost Ghost CVE-2026-70591Ghost: Server-Side Request Forgery in Image FetchingTryGhost Ghost CVE-2026-70590Ghost: Blind Password Hash Disclosure in Ghost Admin APITryGhost Ghost CVE-2026-70588Ghost: Cross-Site Scripting in Universal ImportTryGhost Ghost CVE-2026-59817Ghost: Paid gift memberships obtainable at minimal cost via the donations featureTryGhost Ghost CVE-2026-53950@tryghost/activitypub: XSS in Ghost's ActivityPub clientTryGhost Ghost CVE-2026-53949Ghost Content API filter bypass reveals private fieldsTryGhost Ghost CVE-2026-53947Ghost: Member existence leak via magic link sign-in responseTryGhost Ghost CVE-2026-53945Ghost: Server-side request forgery via DNS rebinding in external request handlingTryGhost Ghost CVE-2026-53944Ghost: Private IP filtering bypass to make server-side requests to internal servicesTryGhost Ghost CVE-2026-53943Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview headerTryGhost Ghost CVE-2026-29784Ghost: Incomplete CSRF protections around OTC useTryGhost Ghost CVE-2026-29053Ghost Vulnerable to Remote Code Execution via Malicious ThemesTryGhost Ghost CVE-2026-26980Ghost has a SQL Injection in its Content APITryGhost Ghost CVE-2026-25552Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For HeaderTryGhost Ghost-CLI CVE-2026-24778Ghost vulnerable to XSS via malicious Portal preview linksTryGhost Ghost CVE-2026-22596Ghost has SQL Injection in Members Activity FeedTryGhost Ghost CVE-2024-43409Ghost's improper authentication allows access to member information and actionsTryGhost Ghost CVE-2023-31133Ghost vulnerable to disclosure of private API fieldsTryGhost Ghost CVE-2021-39192Privilege escalation: all users can access Admin-level API keysTryGhost Ghost 33 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.