Live data from GitHub and npm, updated daily.
Data last fetched: 2026-07-18
10 active CVEs reported via OSV.dev
Ghost has Staff 2FA bypass
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
Member account takeover
Ghost's improper authentication allows access to member information and actions
Ghost vulnerable to remote code execution in locale setting change
Ghost has possible Cross-site Scripting issue
Ghost vulnerable to arbitrary file read via symlinks in content import
DOM XSS in Theme Preview
ghost vulnerable to unauthorized newsletter modification via improper access controls
Ghost has incomplete CSRF protections around OTC use
Other CMS projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Ghost — without relying on volunteer maintainers.