CVE Tools

Ghost

9 CVEs tracked since 2023. Since Jan 2023, none of them reached CISA KEV.

Ghost CVEs per month

Jan 2023 to Jan 2026. Point at a month, or focus the strip and use the arrow keys.
Ghost CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-0140
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-0150

Products

The products that kept showing up in Ghost's monthly top three, with their CVEs summed over those months.

  1. Ghost92 months
  2. Portal11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Ghost.

  1. CVE-2026-29784Ghost: Incomplete CSRF protections around OTC use7.5
  2. CVE-2026-26980Ghost has a SQL Injection in its Content API9.4
  3. CVE-2026-24778Ghost vulnerable to XSS via malicious Portal preview links8.8
  4. CVE-2026-22597Ghost has SSRF via External Media Inliner2.7
  5. CVE-2026-22596Ghost has SQL Injection in Members Activity Feed6.7
  6. CVE-2026-22595Ghost has Staff Token permission bypass8.1
  7. CVE-2026-22594Ghost has Staff 2FA bypass8.1
  8. CVE-2025-9862Ghost 6.0.6 - SSRF via oEmbed Bookmark6.5
  9. CVE-2024-43409Ghost's improper authentication allows access to member information and actions6.5
  10. CVE-2024-34451Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is ...9.1
  11. CVE-2024-34448Ghost before 5.82.0 allows CSV Injection during a member CSV export.8.8
  12. CVE-2024-23724Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile picture that contains JavaScript code to interact wit...9.0
  13. CVE-2024-23725Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries.6.1
  14. CVE-2023-40028Arbitrary file read via symlinks in Ghost4.9
  15. CVE-2023-31133Ghost vulnerable to disclosure of private API fields7.5

The record

Peak rank
#132 in Jan 2023
Busiest month shown
Jan 2026, 5 CVEs
Months with a KEV entry
0 since Jan 2023
Monthly snapshots
2 since 2023
Ghost's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store