Medium severity5.3NVD Advisory· Published Oct 1, 2026
CVE-2026-103274
CVE-2026-103274
Description
Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.