CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-53947

mediumCVSS 5.3covered by 1 sourcefirst seen 2026-08-04
Impact A discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a registered member of a Ghost site. Vulnerable versions This vulnerability is present in Ghost from v5.18.0 up to v6.21.0. Patches v6.21.1 contains a fix for this issue. How to update For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here. If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here. For more information If you have any questions or comments about this advisory, email Ghost at security@ghost.org.

⚡ Watch CVE-2026-53947

Get an email if CVE-2026-53947 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-53947

CVE.org record

Embed the live status

CVE-2026-53947 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-53947 status](https://www.csirts.com/badge/CVE-2026-53947)](https://www.csirts.com/cve/CVE-2026-53947)