Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ghost is a Node.js content management system. From 0.7.2 until 6.64.0, any staff-level user was able to determine the relative ordering of other staff users' hashed passwords. This does not directly disclose password hashes, and does not provide a practical path to recovering a password. This issue is fixed in version 6.64.0. | |
| Title | Ghost: Password Hash Ordering Disclosure in Ghost Admin API | |
| Weaknesses | CWE-203 CWE-943 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T19:54:24.255Z
Reserved: 2026-10-05T16:40:39.613Z
Link: CVE-2026-105652
Updated: 2026-10-05T19:54:20.986Z
Status : Received
Published: 2026-10-05T20:17:14.180
Modified: 2026-10-05T20:17:14.180
Link: CVE-2026-105652
No data.
OpenCVE Enrichment
No data.