HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-103271 — Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that...

·Source: NIST NVD

Updated:

Executive Summary

Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly querying the content API to retrieve restricted posts without authentication.

Analysis

Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly querying the content API to retrieve restricted posts without authentication. CVSS Score: 7.5. Published: 2026-10-01T11:17:22.407.

Indicators of Compromise (1)

CVE (1)
CVE-2026-103271
Source Attribution

Originally published by NIST NVD on Oct 1, 2026. Verified by: NIST.

Related Threats