MEDIUM 5.3 NVD
CVE-2026-103284
Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to
Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks.
References
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-vm82-r49m-224q
- https://www.vulncheck.com/advisories/ghost-5.125.1-before-6.57.1-information-disclosure-vi
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.