#ghost-cms

[ follow ]
#sql-injection
Node JS
fromNist
3 days ago

NVD

Unauthenticated attackers can read arbitrary database data in Ghost versions 3.24.0 through 6.19.0 via an SQL injection flaw, fixed in 6.19.1.
Information security
fromSecurityWeek
4 days ago

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites

CVE-2026-26980 SQL injection in Ghost has been exploited at scale to steal Admin API keys and inject malicious JavaScript into unpatched sites.
Node JS
fromNist
3 days ago

NVD

Unauthenticated attackers can read arbitrary database data in Ghost versions 3.24.0 through 6.19.0 via an SQL injection flaw, fixed in 6.19.1.
Information security
fromSecurityWeek
4 days ago

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites

CVE-2026-26980 SQL injection in Ghost has been exploited at scale to steal Admin API keys and inject malicious JavaScript into unpatched sites.
Information security
fromThe Hacker News
4 days ago

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

A critical Ghost CMS SQL injection flaw enables unauthenticated attackers to steal admin API keys and inject malicious JavaScript for ClickFix poisoning.
[ Load more ]