Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-103272

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Oct 01, 2026
Vendor unknown

Description

Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data. Attackers can observe discrepancies in API metadata responses to enumerate staff members and extract sensitive information without authentication.

References