#ghost-cms

[ follow ]
#sql-injection
Node JS
fromNist
15 hours ago

NVD

Unauthenticated attackers can read arbitrary database data in Ghost versions 3.24.0 through 6.19.0 via an SQL injection flaw, fixed in 6.19.1.
Information security
fromSecurityWeek
1 day ago

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites

CVE-2026-26980 SQL injection in Ghost has been exploited at scale to steal Admin API keys and inject malicious JavaScript into unpatched sites.
Node JS
fromNist
15 hours ago

NVD

Unauthenticated attackers can read arbitrary database data in Ghost versions 3.24.0 through 6.19.0 via an SQL injection flaw, fixed in 6.19.1.
Information security
fromSecurityWeek
1 day ago

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites

CVE-2026-26980 SQL injection in Ghost has been exploited at scale to steal Admin API keys and inject malicious JavaScript into unpatched sites.
Information security
fromThe Hacker News
1 day ago

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

A critical Ghost CMS SQL injection flaw enables unauthenticated attackers to steal admin API keys and inject malicious JavaScript for ClickFix poisoning.
[ Load more ]