Cross-Site Scripting Vulnerability in Ghost from 0.5.3 to 6.50.0
CVE-2026-103292
8.6HIGH
What is CVE-2026-103292?
The vulnerability allows authenticated users with limited privileges to inject unescaped content into the JSON-LD HTML tag, which can be rendered as script content on the published page. This could potentially lead to the compromise of a staff user's admin session when they view the affected page, enabling unauthorized access and manipulation of sensitive content.
Affected Version(s)
Ghost 0.5.3 < 6.50.0
Ghost 6.50.0
