Ghost CMS Content API - SQL Injection
CVE-2026-26980
Verified
Description
Ghost CMS before 6.19.1 is vulnerable to a blind SQL injection in the /ghost/api/content/tags/ endpoint via the filter parameter. This template checks for the vulnerability by sending a boolean-based payload.
Severity
Critical
CVSS Score
9.4
Exploit Probability
5%
Affected Product
ghost
Published Date
March 30, 2026
Template Author
domwhewell-sage
CVE-2026-26980.yaml
9.4Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVE ID:
cve-2026-26980
CWE ID:
cwe-89
Remediation Steps
Upgrade Ghost CMS to version 6.19.1 or later which uses parameterized queries for slug filter ordering.