BIT-ghost-2026-70588

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/ghost/BIT-ghost-2026-70588.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-ghost-2026-70588
Aliases
Published
2026-08-17T05:40:55.495Z
Modified
2026-08-17T08:10:43.189918385Z
Summary
Ghost: Cross-Site Scripting in Universal Import
Details

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.

Database specific
{
    "cpes": [
        "cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / ghost

Package

Name
ghost
Purl
pkg:bitnami/ghost

Severity

  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:L CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
5.26.0
Fixed
6.54.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/ghost/BIT-ghost-2026-70588.json"