Количество 3
Количество 3
CVE-2026-103284
Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks.
CVE-2026-103284
Ghost versions from 5.125.1 before 6.57.1 contain an information discl ...
GHSA-wm9p-jg8j-w38q
Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-103284 Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks. | CVSS3: 4.3 | 0% Низкий | 2 дня назад | |
CVE-2026-103284 Ghost versions from 5.125.1 before 6.57.1 contain an information discl ... | CVSS3: 4.3 | 0% Низкий | 2 дня назад | |
GHSA-wm9p-jg8j-w38q Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks. | CVSS3: 4.3 | 0% Низкий | 2 дня назад |
Уязвимостей на страницу