Skip to content

Known CVE

Ghost CMS Content API - SQL Injection

Ghost CMS before 6.19.1 is vulnerable to a blind SQL injection in the /ghost/api/content/tags/ endpoint via the filter parameter. This template checks for the vulnerability by sending a boolean-based payload.

CVE-2026-26980

Critical2026CVSS 9.4CWE-89

cve2026 · ghost · ghostcms · sqli · vuln · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website