← Späť na vyhľadávanie CVE

CVE-2026-70588

Popis

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.

CVSS 5EPSS 0.258%Riziko 0.51
Zobraziť zdroj
Zverejnené
2026-08-04 21:16:38
Posledná úprava
2026-08-05 19:17:37
Vektor
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:L