Information Disclosure in Ghost Versions by Ghost Foundation
CVE-2026-103284
5.3MEDIUM
What is CVE-2026-103284?
Ghost versions prior to 6.57.1 are vulnerable to an information disclosure issue in the Admin Feedback endpoint. This vulnerability may allow unauthorized staff users to gain access to confidential member data. Attackers with staff privileges can exploit the feedback endpoint, allowing retrieval of sensitive information without undergoing proper authorization checks. This raises significant concerns over data security and the integrity of user information.
Affected Version(s)
Ghost 5.125.1 < 6.57.1
Ghost 6.57.1
