Security: TryGhost/Ghost
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Unauthenticated Stripe Checkout Allowed Member Account Modification and HTML Injection in NewslettersGHSA-qppx-rw6v-xjqf published
Sep 3, 2026 by acburdineHigh -
Staff Could Accept Invite with any EmailGHSA-xcgh-2828-cvmx published
Sep 3, 2026 by acburdineModerate -
Suspended Staff Could Reactivate Accounts with Password ResetGHSA-q734-xjgc-vpj9 published
Sep 3, 2026 by acburdineCritical -
Missing Authorization Allowed Access to Comments and Post Excerpts for Gated ContentGHSA-rv92-9vfp-2826 published
Sep 3, 2026 by acburdineModerate -
Authorization Issue Allowed Author Role to Delete any PostGHSA-x3mg-q38v-m562 published
Sep 3, 2026 by acburdineModerate -
Staff Tokens Granted Elevated Post PrivilegesGHSA-jj85-wvj2-r86m published
Aug 20, 2026 by acburdineModerate -
Unauthenticated Comment Read in Private ModeGHSA-5ppm-p957-x46r published
Aug 20, 2026 by acburdineModerate -
Blind Password Hash Disclosure in Ghost Admin APIGHSA-ghq6-q78f-2cpg published
Aug 20, 2026 by acburdineModerate -
Denied Extension Bypass in Theme Serving via URL EncodingGHSA-6v8p-3jx9-8chr published
Aug 13, 2026 by acburdineModerate -
Editor oEmbed Preview Allows Untrusted Script ExecutionGHSA-8vhf-xxpj-4qrg published
Aug 13, 2026 by acburdineHigh