Medium severity4.3NVD Advisory· Published Oct 1, 2026
CVE-2026-103284
CVE-2026-103284
Description
Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.