CVE-2026-104414

Source
https://cve.org/CVERecord?id=CVE-2026-104414
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104414.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-104414
Aliases
  • GHSA-v3xr-g6p2-fvgv
Published
2026-10-02T11:37:57Z
Modified
2026-10-04T02:45:56Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Ghost from 2.5.0 before 6.64.0 Stored XSS via oEmbed Photo Responses
Details

Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embedding their URL stores scripts that run in the Ghost editor, published site, and newsletter emails, compromising staff admin sessions.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-79"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104414.json"
}
References

Affected packages

Git / github.com/tryghost/ghost

Affected ranges

Type
GIT
Repo
https://github.com/tryghost/ghost
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.5.0"
        },
        {
            "fixed":  "6.64.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104414.json"