# \#docker

**URL:** https://forum.ghost.org/tag/docker/13.md

[Latest](https://forum.ghost.org/latest.md) · [Categories](https://forum.ghost.org/categories.md) · [Tags](https://forum.ghost.org/tags.md)

---

## [Self-hosters left vulnerable to XSS vuln due to second-class Docker support](https://forum.ghost.org/t/self-hosters-left-vulnerable-to-xss-vuln-due-to-second-class-docker-support/61674)

<div class="topic-metadata">

**Author:** [@markstos](https://forum.ghost.org/u/markstos)\
**Replies:** 45\
**Last updated:** [August 18, 2026, 9:33pm UTC](https://forum.ghost.org/t/self-hosters-left-vulnerable-to-xss-vuln-due-to-second-class-docker-support/61674 "2026-08-18T21:33:36Z")

</div>

Ghost 6.15 was released with a security fix for an XSS vulnerability in the portal. Bad actors are now aware of the vulnerable, but no new Docker image is available to install with the fix. A fix is being worked out her…
