Loading market data...
← Back to CVE feed

CVE-2026-103271

HIGH CVSS 7.5 View on NVD ↗

Description

Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly querying the content API to retrieve restricted posts without authentication.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Published: Oct 01, 2026 11:17 UTC Modified: Oct 01, 2026 15:06 UTC