Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token authentication allowed certain endpoints to be accessed that were only intended to be accessible via Staff Session authentication. External systems that have been authenticated via Staff Tokens for Admin/Owner-role users would have had access to these endpoints. This issue has been patched in versions 5.130.6 and 6.11.0.
We have discovered 6,927 live websites that are affected by CVE-2026-22595.
| Product | |
| Category | Headless CMS |
| Vulnerable Domains | 6,927 live websites (50% of Ghost install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 19 versions ( 6.62% of all versions) |
| 5,211 websites | |
| 553 websites | |
| 228 websites | |
| 169 websites | |
| 80 websites | |
| 80 websites | |
| 55 websites | |
| 50 websites | |
| 38 websites | |
| 33 websites |
| .com | 3,753 websites |
| .org | 376 websites |
| .io | 334 websites |
| .net | 289 websites |
| .de | 173 websites |
| .co.uk | 125 websites |
| .co | 98 websites |
| .fr | 87 websites |
| .nl | 70 websites |
| .ca | 58 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.com | *** | ||
| **********.com | *** | ||
| *.*****************.org | *** | ||
| *****.org | *,*** | ||
| ********.com | *,*** | ||
| ************.com | *,*** | ||
| ****.************.com | *,*** | ||
| ****.****.com | *,*** | ||
| ***************.nl | **,*** | ||
| *******.ca | **,*** |
FAQ