Loading market data...
← Back to CVE feed

CVE-2026-103284

MEDIUM CVSS 4.3 View on NVD ↗

Description

Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Published: Oct 01, 2026 11:17 UTC Modified: Oct 01, 2026 15:06 UTC