9.4
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Description
CVE-2026-26980 — Ghost CMS Content API Blind SQL Injection Affected: Ghost 3.24.0 – 6.19.0 Fixed in: Ghost 6.19.1 Auth required: None — Content API key is public Impact: Unauthenticated read of the entire database credentials, API keys ---...
Basic Information
ID
ED8AC01D-C112-5F2F-86B2-002DDA813E82
Published
Jun 26, 2026 at 16:50
Modified
Jun 26, 2026 at 16:53