{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-103284","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-09-30T10:59:26.443Z","datePublished":"2026-10-01T10:42:19.592Z","dateUpdated":"2026-10-01T13:31:23.254Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-10-01T10:42:19.592Z"},"datePublic":"2026-08-13T00:00:00.000Z","title":"Ghost 5.125.1 before 6.57.1 Information Disclosure via Feedback","descriptions":[{"lang":"en","value":"Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Incorrect Authorization","cweId":"CWE-863","type":"CWE"}]}],"affected":[{"vendor":"TryGhost","product":"Ghost","defaultStatus":"unaffected","packageURL":"pkg:npm/ghost","versions":[{"version":"5.125.1","status":"affected","versionType":"semver","lessThan":"6.57.1"},{"version":"6.57.1","status":"unaffected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*","versionStartIncluding":"5.125.1","versionEndExcluding":"6.57.1"}]}]}],"metrics":[{"format":"CVSS","cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}},{"format":"CVSS","cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}],"references":[{"url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-vm82-r49m-224q","tags":["vendor-advisory"],"name":"GitHub Security Advisory (GHSA-vm82-r49m-224q)"},{"name":"VulnCheck Advisory: Ghost 5.125.1 before 6.57.1 Information Disclosure via Feedback","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/ghost-5.125.1-before-6.57.1-information-disclosure-via-feedback"}],"credits":[{"lang":"en","value":"default-cybe","type":"reporter"},{"lang":"en","value":"doanmanhducz","type":"reporter"}],"x_generator":{"engine":"vulncheck-endgame"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-10-01T13:30:35.262552Z","id":"CVE-2026-103284","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-01T13:31:23.254Z"}}]}}