CVE-2026-105652: low-severity vulnerability in TryGhost Ghost
Ghost: Password Hash Ordering Disclosure in Ghost Admin API
Published
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.1epss 0.3%
exploitation probability
0.3%top 84% of all CVEs
observed exploitation
nono source reports it
Ghost is a Node.js content management system. From 0.7.2 until 6.64.0, any staff-level user was able to determine the relative ordering of other staff users' hashed passwords. This does not directly disclose password hashes, and does not provide a practical path to recovering a password. This issue is fixed in version 6.64.0.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
TryGhost · GhostRelated CVEs — TryGhost Ghost
In the same product, most dangerous first.
CVE-2023-40028MEDIUMArbitrary file read via symlinks in GhostEPSS 69.0%CVE-2023-31133HIGHGhost vulnerable to disclosure of private API fieldsEPSS 45.7%CVE-2021-29484MEDIUMDOM XSS in Theme PreviewEPSS 7.9%CVE-2026-29053HIGHGhost Vulnerable to Remote Code Execution via Malicious ThemesEPSS 5.0%CVE-2026-26980CRITICALGhost has a SQL Injection in its Content APIEPSS 5.0%CVE-2026-22594HIGHGhost has Staff 2FA bypassEPSS 1.3%