CVE-2026-103274EPSS p10.3%
CVE-2026-103274CVE-2026-103274
Description
Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.
Scoring
| CVSS | 5.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.21% probability of exploitation · percentile 10.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-01 |