Ghost is a focused publishing and content-management platform with a relatively narrow product portfolio that has accumulated a meaningful vulnerability footprint, reflecting its role in internet-facing web publishing infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a notable tendency toward public exploit availability. The exposure concentrates in the Ghost publishing application and recurs through input-handling and authentication weakness classes including cross-site scripting, server-side request forgery, improper authentication, insecure default initialization, and information disclosure, which are characteristic of web application attack surfaces. Defenders should treat Ghost instances as requiring prompt patch cycles, particularly those exposed to untrusted networks; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ghost over time
Signals from CVEs in this vendor scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-26980HIGH Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed | Feb 20, 2026 | 7.5 | 87 | NO | YES |
CVE-2023-32235HIGH Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal. This occurs in frontend/we | May 5, 2023 | 7.5 | 66 | NO | YES |
CVE-2023-40028MEDIUM Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This | Aug 15, 2023 | 6.5 | 63 | NO | YES |
CVE-2023-31133HIGH Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid subscriptions to members. Prior to version 5.46.1, due to a | May 8, 2023 | 7.5 | 47 | NO | NO |
CVE-2022-41697MEDIUM A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive informati | Dec 22, 2022 | 5.3 | 40 | NO | YES |
CVE-2021-29484MEDIUM Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted users gaining access to Ghost Admin. Attackers can gain acce | Apr 29, 2021 | 6.8 | 36 | NO | YES |
CVE-2022-28397CRITICAL An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed | Apr 12, 2022 | 9.8 | 35 | NO | NO |
CVE-2026-29053CRITICAL Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue | Mar 5, 2026 | 9.8 | 32 | NO | NO |
CVE-2022-27139CRITICAL An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. NOTE: Vendor states that as out | Apr 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-29784HIGH Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to use OTCs in login sessions diff | Mar 7, 2026 | 8.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (34 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ghost.
Media articles that mention a CVE ID that affects a product developed by Ghost — matched by CVE ID, not by vendor name.