SB20260814116 - Multiple vulnerabilities in Ghost



SB20260814116 - Multiple vulnerabilities in Ghost

Published: August 14, 2026

Security Bulletin ID SB20260814116
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: N/A)

CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify comment like or dislike data they are not authorized to delete.

The vulnerability exists due to improper access control in the comment like feature when handling delete requests for comment likes or dislikes. A remote user can send a crafted request to modify comment like or dislike data they are not authorized to delete.


2) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: N/A)

CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper input validation in the comments feature when handling comment access requests. A remote user can send crafted requests to disclose sensitive information.


Remediation

Install update from vendor's website.