Ghost 5.125.1 至 6.57.0(不含)版本中存在一个信息泄露漏洞,位于管理后台的“反馈”(Admin Feedback)端点。该漏洞允许未授权的具有工作人员权限的用户访问成员数据。拥有工作人员权限的攻击者可以通过查询反馈端点,在缺乏适当授权检查的情况下获取敏感成员信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103268 | 8.8 HIGH | Ghost 1.0.0 before 6.62.0 Suspension Bypass via Password Reset |
| CVE-2026-103283 | 8.1 HIGH | Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling |
| CVE-2026-103277 | 8.1 HIGH | Ghost 2.5.0 before 6.34.0 Untrusted Script Execution via oEmbed |
| CVE-2026-103292 | 8.0 HIGH | Ghost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_head |
| CVE-2026-103271 | 7.5 HIGH | Ghost 4.0.0 before 6.63.0 Restricted Content Bypass |
| CVE-2026-103272 | 7.5 HIGH | Ghost 2.10.0 before 6.63.0 Staff Enumeration via Content API |
| CVE-2026-103286 | 7.3 HIGH | Ghost 2.21.0 before 6.56.0 Privilege Escalation via Notifications |
| CVE-2026-103278 | 7.3 HIGH | Ghost 5.8.0 before 6.34.0 Staff Account Takeover via Admin iframe |
| CVE-2026-103266 | 7.1 HIGH | Ghost 5.2.0 before 6.62.0 Unauthenticated Stripe Checkout Account Modification |
| CVE-2026-103279 | 6.8 MEDIUM | Ghost 3.10.0 before 6.34.0 Session Invalidation Bypass |
| CVE-2026-103288 | 6.5 MEDIUM | Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comment Like |
| CVE-2026-103289 | 6.5 MEDIUM | Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comments |
| CVE-2026-103291 | 6.4 MEDIUM | Ghost 3.20.2 before 6.51.0 SSRF via image-size fetch |
| CVE-2026-103281 | 5.4 MEDIUM | Ghost 3.23.0 before 6.23.0 API Key Exposure via Admin API |
| CVE-2026-103274 | 5.3 MEDIUM | Ghost 5.3.0 before 6.58.0 Unauthenticated Comment Read |
| CVE-2026-103280 | 5.3 MEDIUM | Ghost 0.8.0 before 6.23.0 Information Disclosure via Setup Endpoint |
| CVE-2026-103269 | 5.3 MEDIUM | Ghost 5.3.0 before 6.62.0 Missing Authorization via Post Excerpts |
| CVE-2026-103276 | 5.3 MEDIUM | Ghost before 6.20.0 File Read via URL Encoding Bypass |
| CVE-2026-103282 | 4.3 MEDIUM | Ghost 0.5.0 before 6.23.0 Multiple Account Creation via Invite Token |
| CVE-2026-103275 | 4.3 MEDIUM | Ghost 5.42.2 before 6.58.0 Password Hash Disclosure |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet