Description
CVE-2025-66849 Ghost CMS Privilege Escalation PoC Summary In Ghost Foundation Ghost CMS up to 6.4.0, the HTML block within the post draft editor fails to properly sanitize or encode user-supplied content, resulting in a stored cross-site scripting XSS...
Basic Information
ID
B449A2D2-373F-526D-ABF1-E90DAB4E08EA
Published
Apr 13, 2026 at 14:36
Modified
Apr 13, 2026 at 14:44