Medium severity4.3NVD Advisory· Published Oct 1, 2026
CVE-2026-103285
CVE-2026-103285
Description
Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows attackers to submit feedback on behalf of logged-in users. Attackers can craft a malicious link to the feedback page that automatically submits feedback when visited by authenticated members without their knowledge or consent.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.