CVE-2026-103285
EUVD-2026-9067801.10.2026, 11:17
Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows attackers to submit feedback on behalf of logged-in users. Attackers can craft a malicious link to the feedback page that automatically submits feedback when visited by authenticated members without their knowledge or consent.
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration