Back to CVE List

CVE-2026-22594

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.1 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Vulnerability Description

Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA. This issue has been patched in versions 5.130.6 and 6.11.0.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-287
Source
NVD
Vendor
ghost
Product
ghost

External References

Discussion (0)

Add Comment

No comments yet. Be the first!