CVE-2026-70588

MEDIUM

Ghost: Cross-Site Scripting in Universal Import

Title source: cna
STIX 2.1

Description

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.

Scores

CVSS v3 5.0
EPSS 0.0026
EPSS Percentile 17.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
npm/ghost 5.26.0 - 6.54.1npm
TryGhost/Ghost >= 5.26.0, < 6.54.1
Published Aug 04, 2026
Tracked Since Aug 05, 2026