High severity7.5NVD Advisory· Published Oct 1, 2026
CVE-2026-103271
CVE-2026-103271
Description
Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly querying the content API to retrieve restricted posts without authentication.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.