My personal blog got hacked the other day (fortunately for a short time) because I was running a vulnerable version of Ghost.

If you are using Ghost versions 3.24.0 through 6.19.0 you need to upgrade.

https://github.com/advisories/GHSA-w52v-v783-gw97

#ghost

CVE-2026-26980 - GitHub Advisory Database

Ghost has a SQL injection in Content API

GitHub