CVE-2026-103279
- EPSS 0.19%
- Veröffentlicht 01.10.2026 10:42:16
- Zuletzt bearbeitet 06.10.2026 02:17:02
Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access to user accounts even after the associated user changes their password.
CVE-2026-103278
- EPSS 0.27%
- Veröffentlicht 01.10.2026 10:42:15
- Zuletzt bearbeitet 01.10.2026 15:17:27
Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff user accounts. Attackers with content publishing privileges can craft malicious pages that, when visited by acti...
CVE-2026-103277
- EPSS 0.27%
- Veröffentlicht 01.10.2026 10:42:14
- Zuletzt bearbeitet 01.10.2026 15:06:17
Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in the context ...
CVE-2026-103276
- EPSS 0.23%
- Veröffentlicht 01.10.2026 10:42:13
- Zuletzt bearbeitet 01.10.2026 15:06:17
Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL encoding to bypass extension validation and access sensitive theme ...
CVE-2026-103275
- EPSS 0.21%
- Veröffentlicht 01.10.2026 10:42:13
- Zuletzt bearbeitet 06.10.2026 02:17:01
Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in the Admin API bulk post and page edit and delete endpoints, which accept filters on restricted fields such as authors.password, because of an incomplete fix for CVE-2026-7...
CVE-2026-103274
- EPSS 0.21%
- Veröffentlicht 01.10.2026 10:42:12
- Zuletzt bearbeitet 01.10.2026 15:17:26
Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.
CVE-2026-103272
- EPSS 0.37%
- Veröffentlicht 01.10.2026 10:42:11
- Zuletzt bearbeitet 01.10.2026 17:17:18
Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data. Attackers can observe discrepancies in API metadata responses to enumerate staff members an...
CVE-2026-103271
- EPSS 0.38%
- Veröffentlicht 01.10.2026 10:42:10
- Zuletzt bearbeitet 06.10.2026 01:16:33
Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly querying the content API to retrieve restricted posts...
CVE-2026-103269
- EPSS 0.24%
- Veröffentlicht 01.10.2026 10:42:09
- Zuletzt bearbeitet 01.10.2026 15:17:26
Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an authenticated site member to read the excerpts of posts they do not have access to (gated content).
CVE-2026-103268
- EPSS 0.32%
- Veröffentlicht 01.10.2026 10:42:09
- Zuletzt bearbeitet 01.10.2026 15:06:17
Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset oper...