/Vulnerability Library

Ghost CMS Content API - SQL Injection

CVE-2026-26980
Verified

Description

Ghost CMS before 6.19.1 is vulnerable to a blind SQL injection in the /ghost/api/content/tags/ endpoint via the filter parameter. This template checks for the vulnerability by sending a boolean-based payload.

Severity

Critical

CVSS Score

9.4

Exploit Probability

5%

Affected Product

ghost

Published Date

March 30, 2026

Template Author

domwhewell-sage

CVE-2026-26980.yaml
9.4Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVE ID:
cve-2026-26980
CWE ID:
cwe-89

References

https://github.com/TryGhost/Ghost/security/advisories/GHSA-w52v-v783-gw97https://github.com/TryGhost/Ghost/commit/30868d632b2252b638bc8a4c8ebf73964592ed91https://nvd.nist.gov/vuln/detail/CVE-2026-26980

Remediation Steps

Upgrade Ghost CMS to version 6.19.1 or later which uses parameterized queries for slug filter ordering.