SB20260814116 - Multiple vulnerabilities in Ghost
Published: August 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: N/A)
CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify comment like or dislike data they are not authorized to delete.
The vulnerability exists due to improper access control in the comment like feature when handling delete requests for comment likes or dislikes. A remote user can send a crafted request to modify comment like or dislike data they are not authorized to delete.
2) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: N/A)
CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper input validation in the comments feature when handling comment access requests. A remote user can send crafted requests to disclose sensitive information.
Remediation
Install update from vendor's website.