github.com
https://github.com/TryGhost/Ghost CVE-2026-70588
MEDIUM
Ghost: Cross-Site Scripting in Universal Import
Record summary
CVE-2026-70588 has a selected CVSS score of 5.0 (medium).
Description
Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | >= 5.26.0, < 6.54.1 | affected | |
ghostBrowse npm / ghost | GitHub Advisory | 5.26.0 to < 6.54.1 · Fixed in 6.54.1 | affected |
References
5github.com
https://github.com/TryGhost/Ghost/commit/a8bea3a4ceec4c852b880f4885119453c3d8588e github.com
https://github.com/TryGhost/Ghost/pull/29635 github.com
https://github.com/TryGhost/Ghost/releases/tag/v6.54.1 github.comConfirmation
https://github.com/TryGhost/Ghost/security/advisories/GHSA-2gx6-7gx2-wwcf