Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ghost

First CVE: Sep 17, 2019Active for: 7 yearsTotal CVEs: 34
60.4
VTI Score
TOP TARGET

Ghost is a focused publishing and content-management platform with a relatively narrow product portfolio that has accumulated a meaningful vulnerability footprint, reflecting its role in internet-facing web publishing infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a notable tendency toward public exploit availability. The exposure concentrates in the Ghost publishing application and recurs through input-handling and authentication weakness classes including cross-site scripting, server-side request forgery, improper authentication, insecure default initialization, and information disclosure, which are characteristic of web application attack surfaces. Defenders should treat Ghost instances as requiring prompt patch cycles, particularly those exposed to untrusted networks; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
34
Total CVEs
More Total CVEs than 98% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ghost over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 17, 2019
6 years ago
Most Recent CVE
Mar 7, 2026
139 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (34 CVEs).

34 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-26980HIGH
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed
Feb 20, 20267.587NOYES
CVE-2023-32235HIGH
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal. This occurs in frontend/we
May 5, 20237.566NOYES
CVE-2023-40028MEDIUM
Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This
Aug 15, 20236.563NOYES
CVE-2023-31133HIGH
Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid subscriptions to members. Prior to version 5.46.1, due to a
May 8, 20237.547NONO
CVE-2022-41697MEDIUM
A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive informati
Dec 22, 20225.340NOYES
CVE-2021-29484MEDIUM
Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted users gaining access to Ghost Admin. Attackers can gain acce
Apr 29, 20216.836NOYES
CVE-2022-28397CRITICAL
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed
Apr 12, 20229.835NONO
CVE-2026-29053CRITICAL
Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue
Mar 5, 20269.832NONO
CVE-2022-27139CRITICAL
An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. NOTE: Vendor states that as out
Apr 12, 20229.831NONO
CVE-2026-29784HIGH
Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to use OTCs in login sessions diff
Mar 7, 20268.830NONO
View all 34 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products34 CVEs
44%
35%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.9%)
Network33 (97.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (97.1%)
High1 (2.9%)
Unknown0 (0.0%)
User Interaction
None24 (70.6%)
Unknown0 (0.0%)
Required10 (29.4%)
Privileges Required
Low15 (44.1%)
High3 (8.8%)
None16 (47.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (34 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
11.8% of CVEs· 96th percentile
ExploitDB
3 CVEs
8.8% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ghost.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ghost — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ghost's Products

View all 7 CNAs →

Top CWEs