CVE-2026-103276
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Oct 01, 2026
Vendor
unknown
Description
Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL encoding to bypass extension validation and access sensitive theme files.