Loading market data...
← Back to CVE feed

CVE-2026-104414

HIGH CVSS 8.1 View on NVD ↗

Description

Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embedding their URL stores scripts that run in the Ghost editor, published site, and newsletter emails, compromising staff admin sessions.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Published: Oct 02, 2026 12:17 UTC Modified: Oct 02, 2026 18:17 UTC