Ouch, this is really not a good look for Ghost,
@johnonolanJohn O'Nolan
βGhost (CMS) took some heat from the community for a longstanding SQL vulnerability not being addressed in the project's Docker imageβ
Edit: They owned up to it, and have a plan in place to fix: https://forum.ghost.org/t/self-hosters-left-vulnerable-to-xss-vuln-due-to-second-class-docker-support/61674/38
