{"id":"BIT-ghost-2026-26980","summary":"Ghost has a SQL Injection in its Content API","details":"Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.","aliases":["CVE-2026-26980","GHSA-w52v-v783-gw97"],"modified":"2026-09-10T16:01:31.765251315Z","published":"2026-02-21T08:39:22.999Z","database_specific":{"severity":"Critical","cpes":["cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*"]},"references":[{"type":"FIX","url":"https://github.com/TryGhost/Ghost/commit/30868d632b2252b638bc8a4c8ebf73964592ed91"},{"type":"ARTICLE","url":"https://github.com/TryGhost/Ghost/releases/tag/v6.19.1"},{"type":"ADVISORY","url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-w52v-v783-gw97"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26980"},{"type":"WEB","url":"https://blog.xlab.qianxin.com/ghost-cms-page-poisoning-cve-2026-26980/"}],"affected":[{"package":{"name":"ghost","ecosystem":"Bitnami","purl":"pkg:bitnami/ghost"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.24.0"},{"fixed":"6.19.1"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/ghost/BIT-ghost-2026-26980.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"}]}],"schema_version":"1.9.0"}