What is CVE-2026-70588?
The Universal Import feature in Ghost CMS allowed Stored XSS in post content due to improper sanitization of imported data, affecting versions 5.26.0 to 6.54.1. This vulnerability could enable malicious script execution via the admin panel. Upgrading to version 6.54.1 resolves the issue.
Azərbaycanca: Ghost CMS-in Universal Import funksiyasında daxil olunan məzmunun düzgün təmizlənməməsi səbəbindən post məzmununda saxlanılan XSS zəifliyi aşkar edilib. Bu boşluq 5.26.0 ilə 6.54.1 versiyaları arasında təsir göstərir və administratorların panelinə yüklənmiş zərərli skriptlərin işə düşməsinə yol aça bilər. Təsirə məruz qalan sistemlər üçün dərhal 6.54.1 versiyasına yeniləmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Where can an attacker execute a malicious script using the Stored XSS vulnerability in Ghost CMS?
This vulnerability could allow malicious scripts imported into the admin panel to be executed.
Which versions does this XSS vulnerability affect in Ghost CMS?
This security vulnerability affects Ghost CMS versions 5.26.0 to 6.54.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.