CPE
high
advisory
Stored XSS in Ghost via File Uploads
2 TTPs 1 CVEGhost versions 6.22.1 through 6.64.0 are vulnerable to stored cross-site scripting due to improper Content-Type handling in the local storage adapter, allowing staff-level users to execute malicious scripts on the site domain.
Ghost
web-application
xss
cve-2026-105679
2t
1c
high
threat
Unauthenticated Stripe Checkout Manipulation in Ghost
9 TTPs 1 CVEA vulnerability in Ghost versions 5.2.0 through 6.61.9 allows unauthenticated remote attackers to manipulate Stripe Checkout flows to modify member records and inject malicious content into newsletters.
exploited
Ghost +7
web-vulnerability
xss
application-security
enumeration
api-security
remote-code-execution
vulnerability
cms
9t
1c
updated