Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-15
10 active CVEs reported via OSV.dev
Ghost has Staff 2FA bypass
Member account takeover
Ghost's improper authentication allows access to member information and actions
Ghost vulnerable to remote code execution in locale setting change
Ghost has possible Cross-site Scripting issue
Ghost vulnerable to arbitrary file read via symlinks in content import
DOM XSS in Theme Preview
ghost vulnerable to unauthorized newsletter modification via improper access controls
Ghost has incomplete CSRF protections around OTC use
Ghost has Staff Token permission bypass
Other CMS projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Ghost โ without relying on volunteer maintainers.
Talk to an Expert โ