The professional publishing platform
82%
Total Score
100
1
91
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-53949 ghost is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 5.46.1 - 6.21.2. | 5.46.1 - 6.21.2 | Medium |
CVE-2026-70596 ghost is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.9.0 - 6.54.1. | 4.9.0 - 6.54.1 | Medium |
CVE-2026-70595 ghost is vulnerable to Server-Side Request Forgery (SSRF) in versions 6.26.0 - 6.54.1. | 6.26.0 - 6.54.1 | Medium |
CVE-2026-59817 ghost is vulnerable to External Control of Assumed-Immutable Web Parameter in versions 6.27.0 - 6.44.0. | 6.27.0 - 6.44.0 | Medium |
CVE-2026-53947 ghost is vulnerable to Observable Response Discrepancy in versions 5.18.0 - 6.21.1. | 5.18.0 - 6.21.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
got Version 15.1.0 | — | — |
rss Version 1.2.2 | — | — |
xml Version 1.0.1 | — | — |
zod Version 4.4.3 | — | — |
clsx Version 2.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant