CVE WATCH / VULNERABILITY DETAIL
CVE-2026-105650
HIGHCVSS 8.1NVD feed
Published 5 October 2026 · tracked since 6 October 2026
Description
Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-95264
- CVE-2026-97257 HIGH 8.8
- CVE-2026-93617 HIGH 7.2
- CVE-2026-105766 LOW 3.1
- CVE-2026-105767 LOW 3.3
- CVE-2026-105683 LOW 3.8
- CVE-2026-105681 MEDIUM 6.5
- CVE-2026-105682 LOW 2.7
- CVE-2026-105679 HIGH 7.3
- CVE-2026-105680 MEDIUM 6.5