XSS Vulnerability in Ghost CMS's Universal Import Feature
CVE-2026-70588

5MEDIUM

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-70588?

The Universal Import feature in the Ghost content management system, ranging from versions 5.26.0 to 6.54.1, has a security flaw that allows improperly sanitized imported content to lead to Cross-Site Scripting (XSS) within post content. Due to this vulnerability, users may find themselves exposed to malicious scripts. It is advised to upgrade to version 6.54.1, where this issue has been addressed.

Affected Version(s)

Ghost >= 5.26.0, < 6.54.1

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.