Stored Cross-Site Scripting in Ghost CMS by Ghost Foundation
CVE-2026-105643
7.3HIGH
What is CVE-2026-105643?
Ghost CMS, developed by Ghost Foundation, is susceptible to stored cross-site scripting vulnerabilities in versions from 6.34.0 through 6.67.0. This security flaw enables staff users, including contributors, to embed malicious scripts within post content that are executed when another staff user accesses the post in the editor. Such exploitation could potentially compromise the affected user's administrative session. To mitigate this risk, self-hosted installations are advised to maintain the default configuration setting of security.embedPreviewUrl. The issue has been resolved in version 6.67.0.
Affected Version(s)
Ghost >= 6.34.0, < 6.67.0
