CVE WATCH / VULNERABILITY DETAIL
CVE-2026-105682
LOWCVSS 2.7NVD feed
Published 5 October 2026 · tracked since 6 October 2026
Description
Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an SSRF vulnerability in the webhooks feature allowed staff users to probe internal hosts from the Ghost server. This issue is fixed in version 6.27.0.
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-95264
- CVE-2026-97257 HIGH 8.8
- CVE-2026-93617 HIGH 7.2
- CVE-2026-105766 LOW 3.1
- CVE-2026-105767 LOW 3.3
- CVE-2026-105683 LOW 3.8
- CVE-2026-105681 MEDIUM 6.5
- CVE-2026-105679 HIGH 7.3
- CVE-2026-105680 MEDIUM 6.5
- CVE-2026-105651 HIGH 7.3