Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-103288

3 дня назад

Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment engagement data.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-103288

3 дня назад

Ghost, an open-source publishing platform, contains an input validatio ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-wj4w-mc24-pcfm

3 дня назад

Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment engagement data.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-103288

Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment engagement data.

CVSS3: 6.5
0%
Низкий
3 дня назад
debian логотип
CVE-2026-103288

Ghost, an open-source publishing platform, contains an input validatio ...

CVSS3: 6.5
0%
Низкий
3 дня назад
github логотип
GHSA-wj4w-mc24-pcfm

Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment engagement data.

CVSS3: 6.5
0%
Низкий
3 дня назад

Уязвимостей на страницу