CVE-2026-105650 - Ghost: Stored XSS via oEmbed Photo Responses
CVE ID :CVE-2026-105650 Published : Oct. 5, 2026, 8:17 p.m. | 1 hour, 11 minutes ago Description :Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These...