Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.
PoC: ghost-cve-2026-26980
CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab (unauthenticated blind SQLi via slug filter ordering)
PoC: CVE-2026-26980
Ghost Content API SQL Injection
[POC] MAL-2026-2307 — CVE-2026-26980-PoC
Ghost CMS Content API Blind SQL Injection
[POC] GHSA-3mgp-fx93-9xv5 — CVE-2026-26980-Ghost-CMS-Api
CVE-2026-26980 - Ghost CMS Content API SQL Injection
PoC: Ghost-CMS-Code-Injection-Audit-CVE-2026-26980
Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass clear and edit code injection fields.
PoC: CVE-2026-26980
[CVE-2026-26980] 👻 Ghost CMS Unauthenticated SQLi via Content API
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free