Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

FeedsContatoPrivacidade© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
Ghost-CMS-Code-Injection-Audit-CVE-2026-26980 — Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass clear and edit code injection fields. | Kitploit
Ferramentas/GitHubGitHub/kulik-labs-development/ghost-cms-code-injection-audit-cve-2026-26980
Defensive ToolsVulnerability ScannersCode AnalysisWeb SecurityMisconfigurationIncident Response
GitHubkulik-labs-development/ghost-cms-code-injection-audit-cve-2026-26980

Ghost-CMS-Code-Injection-Audit-CVE-2026-26980

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass clear and edit code injection fields.

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Ver Repositório
13há 1 mêsAinda não revisado
Compartilhar
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

Ghost CMS Code Injection Cleaner

Removes injected code from every post and page on a Ghost CMS website via the Admin API.

Use this to clean up a compromised Ghost site — for example, one affected by the code injection vulnerability CVE-2026-26980 — by stripping attacker-supplied <script> tags and other injected markup out of the per-post and per-page Header and Footer code injection fields.

It is safe by default (dry-run first, then apply) and strictly scoped: it only clears those two per-post fields. Site-wide code injection (Ghost Admin → Settings → Code injection), post content, and all other settings are never touched.


Requirements

  • Python 3.8+
  • Two pip packages (see requirements.txt):
pip install -r requirements.txt

Setup

1. Get your Admin API key

  1. Log into Ghost Admin
  2. Go to Settings → Integrations
  3. Click Add custom integration, give it a name (e.g. "Cleaner")
  4. Copy the Admin API Key — it looks like:
    6478abc123def456:8f9e0d1c2b3a4567890abcdef1234567890abcdef1234567890abcdef12345678
    

2. Create the config file

Create a file called ghost_cleaner_config.json in the same directory as the script:

{
  "ghost_url": "https://yourdomain.com",
  "admin_api_key": "YOUR_KEY_ID:YOUR_KEY_SECRET"
}

If you skip this step, the script will create an example config file for you on first run and exit — just fill it in and re-run.


Usage

Dry-run (safe, no changes written)

Always run this first to see exactly what would be cleared before touching anything:

python3 ghost_injection_cleaner.py

Example output:

  Ghost Injection Remover
  Mode  : DRY-RUN (read-only)
  Target: https://yourdomain.com

  NOTE: /ghost/api/admin/settings/ (site-wide injection) is
        never read or written by this script.

============================================================
  POSTS
============================================================
  47 posts fetched.

  ✦  'My First Post'
     HEAD: '<script>(function(){var _x="...obfuscated..."</script>'
      🔍  DRY-RUN - would be cleared.

============================================================
  PAGES
============================================================
  6 pages fetched.

============================================================
  SUMMARY
============================================================
  Would clear  : 1 posts/pages
  Already clean: 52 posts/pages

  Re-run with --apply to commit these changes.

Apply changes

Once you're happy with the dry-run output, run with --apply. You'll be prompted to confirm:

python3 ghost_injection_cleaner.py --apply
  Type YES to confirm changes to posts and pages: YES
  ...
  ✅  Cleared.

Use a custom config file path

python3 ghost_injection_cleaner.py --config /path/to/my_config.json

What it clears

For every post and page, it sets both of these fields to null:

FieldLocation in Ghost editor
codeinjection_headPost/page settings → Code injection → Header
codeinjection_footPost/page settings → Code injection → Footer

Posts and pages that have no injection are silently skipped.


What it does NOT touch

  • Site-wide header/footer injection — Ghost Admin → Settings → Code injection
  • Post/page content (the actual body of your posts)
  • Theme files
  • Any Ghost settings other than the two fields listed above

Troubleshooting

Missing dependencies Run pip install -r requirements.txt and try again.

admin_api_key must be in 'id:secret' format Make sure your key has a colon in the middle. It should look like two hex strings separated by :. Copy it directly from Ghost Admin without adding spaces.

ERROR: Ghost API returned HTTP 401 Your Admin API key may be wrong or the integration may have been deleted. Go back to Ghost Admin → Settings → Integrations and verify.

ConnectionError or timeout Check that ghost_url in your config is correct and the site is reachable from the machine you're running the script on.

The script hangs on a large site Each page of 50 posts generates a fresh JWT and waits for the API. This is normal — give it a minute.

Baixar ferramenta