Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sen
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-103268 | 8.8 HIGH | Ghost 1.0.0 before 6.62.0 Suspension Bypass via Password Reset |
| CVE-2026-103283 | 8.1 HIGH | Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling |
| CVE-2026-103277 | 8.1 HIGH | Ghost 2.5.0 before 6.34.0 Untrusted Script Execution via oEmbed |
| CVE-2026-103292 | 8.0 HIGH | Ghost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_head |
| CVE-2026-103271 | 7.5 HIGH | Ghost 4.0.0 before 6.63.0 Restricted Content Bypass |
| CVE-2026-103272 | 7.5 HIGH | Ghost 2.10.0 before 6.63.0 Staff Enumeration via Content API |
| CVE-2026-103286 | 7.3 HIGH | Ghost 2.21.0 before 6.56.0 Privilege Escalation via Notifications |
| CVE-2026-103278 | 7.3 HIGH | Ghost 5.8.0 before 6.34.0 Staff Account Takeover via Admin iframe |
| CVE-2026-103266 | 7.1 HIGH | Ghost 5.2.0 before 6.62.0 Unauthenticated Stripe Checkout Account Modification |
| CVE-2026-103279 | 6.8 MEDIUM | Ghost 3.10.0 before 6.34.0 Session Invalidation Bypass |
| CVE-2026-103288 | 6.5 MEDIUM | Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comment Like |
| CVE-2026-103289 | 6.5 MEDIUM | Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comments |
| CVE-2026-103291 | 6.4 MEDIUM | Ghost 3.20.2 before 6.51.0 SSRF via image-size fetch |
| CVE-2026-103281 | 5.4 MEDIUM | Ghost 3.23.0 before 6.23.0 API Key Exposure via Admin API |
| CVE-2026-103274 | 5.3 MEDIUM | Ghost 5.3.0 before 6.58.0 Unauthenticated Comment Read |
| CVE-2026-103280 | 5.3 MEDIUM | Ghost 0.8.0 before 6.23.0 Information Disclosure via Setup Endpoint |
| CVE-2026-103269 | 5.3 MEDIUM | Ghost 5.3.0 before 6.62.0 Missing Authorization via Post Excerpts |
| CVE-2026-103276 | 5.3 MEDIUM | Ghost before 6.20.0 File Read via URL Encoding Bypass |
| CVE-2026-103282 | 4.3 MEDIUM | Ghost 0.5.0 before 6.23.0 Multiple Account Creation via Invite Token |
| CVE-2026-103275 | 4.3 MEDIUM | Ghost 5.42.2 before 6.58.0 Password Hash Disclosure |
显示前 20 条,共 26 条。 查看全部 → →
暂无评论