Stored Cross-Site Scripting in Ghost CMS by Ghost Foundation
CVE-2026-105643

7.3HIGH

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105643?

Ghost CMS, developed by Ghost Foundation, is susceptible to stored cross-site scripting vulnerabilities in versions from 6.34.0 through 6.67.0. This security flaw enables staff users, including contributors, to embed malicious scripts within post content that are executed when another staff user accesses the post in the editor. Such exploitation could potentially compromise the affected user's administrative session. To mitigate this risk, self-hosted installations are advised to maintain the default configuration setting of security.embedPreviewUrl. The issue has been resolved in version 6.67.0.

Affected Version(s)

Ghost >= 6.34.0, < 6.67.0

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.