HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-103271 — Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that...
·Source: NIST NVD
Updated:
Executive Summary
Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly querying the content API to retrieve restricted posts without authentication.
Analysis
Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly querying the content API to retrieve restricted posts without authentication. CVSS Score: 7.5. Published: 2026-10-01T11:17:22.407.