Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting in compromise of a staff user's admin session. This issue is fixed in version 6.64.0. | |
| Title | Ghost: Stored XSS via oEmbed Photo Responses | |
| Weaknesses | CWE-184 CWE-79 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T19:07:50.271Z
Reserved: 2026-10-05T16:40:39.613Z
Link: CVE-2026-105650
No data.
Status : Received
Published: 2026-10-05T20:17:13.817
Modified: 2026-10-05T20:17:13.817
Link: CVE-2026-105650
No data.
OpenCVE Enrichment
Updated: 2026-10-05T21:15:15Z