CVE-2026-104414
Received Received - Intake

Stored XSS in Ghost CMS via Malicious oEmbed Photo Responses

Vulnerability report for CVE-2026-104414, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embedding their URL stores scripts that run in the Ghost editor, published site, and newsletter emails, compromising staff admin sessions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
tryghost ghost From 2.5.0 (inc) to 6.64.0 (exc)
ghost ghost to 6.64.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Ghost CMS versions 2.5.0 to 6.64.0 have a stored cross-site scripting (XSS) vulnerability via oEmbed photo responses. Attackers can inject malicious scripts into post content by hosting a controlled oEmbed photo response. These scripts execute in the Ghost editor, published site, and newsletter emails, potentially compromising staff admin sessions.

Detection Guidance

To detect this vulnerability, check Ghost CMS versions between 2.5.0 and 6.64.0. Use commands like 'ghost version' in the Ghost CLI or inspect package.json for version details. Look for suspicious oEmbed photo responses in posts or emails that may contain injected scripts.

Impact Analysis

This vulnerability allows attackers to steal admin session cookies, execute unauthorized actions, or inject malicious content into your site. It affects Ghost editor, published content, and newsletter emails, potentially leading to data breaches or account takeovers.

Compliance Impact

This XSS vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules. It may result in data breaches, unauthorized disclosures, and non-compliance with confidentiality provisions.

Mitigation Strategies

Immediately update Ghost CMS to version 6.64.0 or later to patch the vulnerability. Review all posts and newsletters for malicious oEmbed URLs or scripts. Monitor admin sessions for unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104414. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart