CVE WATCH / VULNERABILITY DETAIL
CVE-2026-104414
HIGHCVSS 8.1NVD feed
Published 2 October 2026 · tracked since 3 October 2026
Description
Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embedding their URL stores scripts that run in the Ghost edi
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-104466 MEDIUM 5.4
- CVE-2026-104460 HIGH 7.5
- CVE-2026-104454 MEDIUM 5.3
- CVE-2026-104457 HIGH 8.6
- CVE-2026-104450 MEDIUM 6.5
- CVE-2026-104439 MEDIUM 5.3
- CVE-2026-104440 MEDIUM 5.3
- CVE-2026-104441 MEDIUM 5.3
- CVE-2026-96990
- CVE-2026-94651