Medium severity5.3NVD Advisory· Published Oct 1, 2026
CVE-2026-103276
CVE-2026-103276
Description
Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL encoding to bypass extension validation and access sensitive theme files.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.