Loading market data...
← Back to CVE feed

CVE-2026-103274

MEDIUM CVSS 5.3 View on NVD ↗

Description

Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Published: Oct 01, 2026 11:17 UTC Modified: Oct 01, 2026 15:17 UTC