Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Doanmanhducz

#17552of 57,242
16.7Total CVSS
Vulnerabilities · 3
Medium
2
High
1
PT-2026-103800
4.3
2026-10-01
Tryghost · Ghost · CVE-2026-103267
Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. Attackers can accept leaked invite tokens with attacker-controlled email addresses, or legitimate recipients can register with unintended email providers.
PT-2026-103815
8.1
2026-10-01
Tryghost · Ghost · CVE-2026-103283
Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions.
PT-2026-103816
4.3
2026-10-01
Tryghost · Ghost · CVE-2026-103284
Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks.