← Zurück zur CVE-Suche

CVE-2026-70588

Beschreibung

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.

CVSS 5EPSS 0.258%Risiko 0.51
Quelle öffnen
Veröffentlicht
2026-08-04 21:16:38
Zuletzt geändert
2026-08-05 19:17:37
Vektor
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:L