Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 06 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting in compromise of a staff user's admin session. This issue is fixed in version 6.64.0. | |
| Title | Ghost: Stored XSS via oEmbed Photo Responses | |
| Weaknesses | CWE-184 CWE-79 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T13:38:33.897Z
Reserved: 2026-10-05T16:40:39.613Z
Link: CVE-2026-105650
Updated: 2026-10-06T13:38:27.177Z
Status : Received
Published: 2026-10-05T20:17:13.817
Modified: 2026-10-06T14:17:38.107
Link: CVE-2026-105650
No data.
OpenCVE Enrichment
Updated: 2026-10-05T21:15:15Z