Live data from GitHub and npm, updated daily.
Data last fetched: 2026-08-24
10 active CVEs reported via OSV.dev
Ghost: Cross-Site Scripting in Universal Import
Ghost: Archived Offers can be Redeemed
Ghost has Staff 2FA bypass
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
Member account takeover
Ghost's improper authentication allows access to member information and actions
Ghost: Session Fixation in Ghost Admin
Ghost vulnerable to remote code execution in locale setting change
Ghost: File Upload Content-Type Spoofing
Ghost has possible Cross-site Scripting issue
Other CMS projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Ghost — without relying on volunteer maintainers.