Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-103287 | LOW | 2.7 | Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webhooks feature that allows staff users to probe internal hosts. Attackers with … | Oct 01, 2026 |
| CVE-2026-103286 | HIGH | 7.3 | Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff … | Oct 01, 2026 |
| CVE-2026-103285 | MEDIUM | 4.3 | Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows attackers to submit feedback on behalf … | Oct 01, 2026 |
| CVE-2026-103284 | MEDIUM | 4.3 | Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. … | Oct 01, 2026 |
| CVE-2026-103283 | HIGH | 8.1 | Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only … | Oct 01, 2026 |
| CVE-2026-103282 | MEDIUM | 4.3 | Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a single … | Oct 01, 2026 |
| CVE-2026-103281 | MEDIUM | 5.4 | Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts. An authenticated low-privilege … | Oct 01, 2026 |
| CVE-2026-103280 | MEDIUM | 5.3 | Ghost from version 0.8.0 before 6.23.0 contains an information disclosure vulnerability in its setup endpoint: the endpoint responds to unauthenticated requests with the site owner's … | Oct 01, 2026 |
| CVE-2026-103279 | MEDIUM | 6.8 | Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access … | Oct 01, 2026 |
| CVE-2026-103278 | HIGH | 7.3 | Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff user accounts. Attackers with … | Oct 01, 2026 |
| CVE-2026-103277 | HIGH | 8.1 | Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers … | Oct 01, 2026 |
| CVE-2026-103276 | MEDIUM | 5.3 | Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL … | Oct 01, 2026 |
| CVE-2026-103275 | MEDIUM | 4.3 | Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in the Admin API bulk post and page edit and delete endpoints, which accept filters on … | Oct 01, 2026 |
| CVE-2026-103274 | MEDIUM | 5.3 | Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, … | Oct 01, 2026 |
| CVE-2026-103273 | MEDIUM | 4.3 | Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with … | Oct 01, 2026 |
| CVE-2026-103272 | HIGH | 7.5 | Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data. Attackers can … | Oct 01, 2026 |
| CVE-2026-103271 | HIGH | 7.5 | Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions … | Oct 01, 2026 |
| CVE-2026-103269 | MEDIUM | 5.3 | Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an authenticated site member to read the excerpts of posts they do not … | Oct 01, 2026 |
| CVE-2026-103268 | HIGH | 8.8 | Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended … | Oct 01, 2026 |
| CVE-2026-103267 | MEDIUM | 4.3 | Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. … | Oct 01, 2026 |
| CVE-2026-103266 | HIGH | 7.1 | Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription … | Oct 01, 2026 |
| CVE-2026-103265 | MEDIUM | 4.3 | Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results … | Oct 01, 2026 |
| CVE-2026-103264 | CRITICAL | 9.1 | Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to … | Oct 01, 2026 |
| CVE-2026-103263 | MEDIUM | 5.9 | Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within … | Oct 01, 2026 |
| CVE-2026-103262 | HIGH | 7.5 | Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed … | Oct 01, 2026 |