<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ghost-Cms on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/ghost-cms/</link><description>Recent content in Ghost-Cms on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 26 May 2026 12:51:20 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/ghost-cms/index.xml" rel="self" type="application/rss+xml"/><item><title>Ghost CMS SQL Injection Stole Admin Keys From 700 Websites With One Request</title><link>https://hackingpassion.com/ghost-cms-cve-2026-26980/</link><pubDate>Tue, 26 May 2026 12:51:20 +0200</pubDate><guid>https://hackingpassion.com/ghost-cms-cve-2026-26980/</guid><description>&lt;p>A &lt;strong>SQL injection vulnerability&lt;/strong> in &lt;strong>Ghost CMS&lt;/strong> has turned Harvard University, Oxford University, and DuckDuckGo into malware distribution platforms. Visitors arrive at a page they trust completely, a fake Cloudflare verification prompt appears, and their machine gets infected if they follow the instructions. More than &lt;strong>700 sites&lt;/strong>. Software that had never had an unauthenticated critical vulnerability in its entire history.&lt;/p>
&lt;p>&lt;strong>Ghost CMS&lt;/strong> is publishing software built on Node.js, used for newsletters, membership sites, and independent blogs. It is open source and free to self-host, with a paid hosted version called Ghost Pro. More than &lt;strong>100,000 active installations&lt;/strong> and more than &lt;strong>50,000 GitHub stars&lt;/strong>.&lt;/p></description></item></channel></rss>