CVE-2026-26980

high
Published 2026-02-20 · Modified 2026-05-12
CVSS v3
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVSS v2
VIR risk
7.5

Description

Ghost has a SQL injection in Content API

Predictions

Exploit likelihood
83%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/TryGhost/Ghost/security/advisories/GHSA-w52v-v783-gw97

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/TryGhost/Ghost/releases/tag/v6.19.1

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/TryGhost/Ghost/commit/30868d632b2252b638bc8a4c8ebf73964592ed91

Package impact

EcosystemPackageVulnerableFixed
npm npmghost>=3.24.0,<6.19.16.19.1
npm NPMghost>= 3.24.0, < 6.19.16.19.1

Application impact

VendorProductVersionsFixed
ghostghost{"startIncluding":"3.24.0","endExcluding":"6.19.1"}6.19.1

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.