Skip to main content
Loading…
    CVE-2026-29784 — Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to use OTCs in login sessions different from the reque — CVE Database · The Intelligence Room