CVE-2026-103272

high

Description

Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data. Attackers can observe discrepancies in API metadata responses to enumerate staff members and extract sensitive information without authentication.

References

https://www.vulncheck.com/advisories/ghost-2.10.0-before-6.63.0-staff-enumeration-via-content-api

https://github.com/TryGhost/Ghost/security/advisories/GHSA-ffmj-3ppp-cj4r

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-90665

Details

Source: Mitre, NVD

Published: 2026-10-01

Updated: 2026-10-01

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

CVSS v4

Base Score: 8.7

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00365