OSS Support Hub / CMS

Node.js CMS MIT Latest: v6.38.0

Ghost

Fiercely independent open source publishing platform for modern journalism and content creation

Project Health at a Glance

Live data from GitHub and npm, updated daily.

โญ
52.8K+4
GitHub Stars
๐Ÿ“ฆ
v6.38.0
Latest Release ยท 2 days ago
๐Ÿ”„
4d
Avg. Release Cadence
๐Ÿ›
272
Open Issues
๐Ÿ“…
Today
Last Commit
โฌ‡๏ธ
11.9K
Weekly Downloads
๐Ÿ”’
10
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Ghost has Staff 2FA bypass

Published: 2026-01-08 Fixed in: 6.11.0

Member account takeover

Published: 2021-09-23 Fixed in: 3.42.6

Ghost's improper authentication allows access to member information and actions

Published: 2024-08-20 Fixed in: 5.89.5

Ghost vulnerable to remote code execution in locale setting change

Published: 2022-06-17 Fixed in: 4.48.2

Ghost has possible Cross-site Scripting issue

Published: 2024-02-11 No fix available

Ghost vulnerable to arbitrary file read via symlinks in content import

Published: 2023-08-15 Fixed in: 5.59.1

DOM XSS in Theme Preview

Published: 2021-04-29 Fixed in: 4.3.3

ghost vulnerable to unauthorized newsletter modification via improper access controls

Published: 2022-11-28 Fixed in: 5.22.7

Ghost has incomplete CSRF protections around OTC use

Published: 2026-03-05 Fixed in: 6.19.3

Ghost has Staff Token permission bypass

Published: 2026-01-08 Fixed in: 6.11.0

Alternatives to Ghost

Other CMS projects in the Node.js ecosystem worth evaluating.

Support Options for Ghost

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Ghost โ€” without relying on volunteer maintainers.

Talk to an Expert โ†’