Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54243
Total
4300
Critical
16125
High
15819
Medium
CVE ID Severity Score Description Published
CVE-2026-103287 LOW 2.7 Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webhooks feature that allows staff users to probe internal hosts. Attackers with … Oct 01, 2026
CVE-2026-103286 HIGH 7.3 Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff … Oct 01, 2026
CVE-2026-103285 MEDIUM 4.3 Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows attackers to submit feedback on behalf … Oct 01, 2026
CVE-2026-103284 MEDIUM 4.3 Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. … Oct 01, 2026
CVE-2026-103283 HIGH 8.1 Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only … Oct 01, 2026
CVE-2026-103282 MEDIUM 4.3 Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a single … Oct 01, 2026
CVE-2026-103281 MEDIUM 5.4 Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts. An authenticated low-privilege … Oct 01, 2026
CVE-2026-103280 MEDIUM 5.3 Ghost from version 0.8.0 before 6.23.0 contains an information disclosure vulnerability in its setup endpoint: the endpoint responds to unauthenticated requests with the site owner's … Oct 01, 2026
CVE-2026-103279 MEDIUM 6.8 Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access … Oct 01, 2026
CVE-2026-103278 HIGH 7.3 Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff user accounts. Attackers with … Oct 01, 2026
CVE-2026-103277 HIGH 8.1 Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers … Oct 01, 2026
CVE-2026-103276 MEDIUM 5.3 Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL … Oct 01, 2026
CVE-2026-103275 MEDIUM 4.3 Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in the Admin API bulk post and page edit and delete endpoints, which accept filters on … Oct 01, 2026
CVE-2026-103274 MEDIUM 5.3 Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, … Oct 01, 2026
CVE-2026-103273 MEDIUM 4.3 Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with … Oct 01, 2026
CVE-2026-103272 HIGH 7.5 Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data. Attackers can … Oct 01, 2026
CVE-2026-103271 HIGH 7.5 Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions … Oct 01, 2026
CVE-2026-103269 MEDIUM 5.3 Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an authenticated site member to read the excerpts of posts they do not … Oct 01, 2026
CVE-2026-103268 HIGH 8.8 Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended … Oct 01, 2026
CVE-2026-103267 MEDIUM 4.3 Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. … Oct 01, 2026
CVE-2026-103266 HIGH 7.1 Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription … Oct 01, 2026
CVE-2026-103265 MEDIUM 4.3 Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results … Oct 01, 2026
CVE-2026-103264 CRITICAL 9.1 Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to … Oct 01, 2026
CVE-2026-103263 MEDIUM 5.9 Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within … Oct 01, 2026
CVE-2026-103262 HIGH 7.5 Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed … Oct 01, 2026