CVE-2026-103285
Received Received - Intake

Cross-Site Request Forgery in Ghost CMS

Vulnerability report for CVE-2026-103285, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows attackers to submit feedback on behalf of logged-in users. Attackers can craft a malicious link to the feedback page that automatically submits feedback when visited by authenticated members without their knowledge or consent.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ghost ghost to 6.57.1 (exc)
tryghost ghost From 5.19.0 (inc) to 6.57.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Cross-Site Request Forgery (CSRF) vulnerability in Ghost CMS versions 5.19.0 to 6.57.0. It allows attackers to submit feedback on behalf of logged-in users without their consent by tricking them into clicking a malicious link. The feedback is submitted automatically when the link is visited.

Detection Guidance

To detect this CSRF vulnerability in Ghost CMS, check the installed version using Ghost CLI with 'ghost version' or inspect Docker images for versions between 5.19.0 and 6.57.0. Review server logs for unusual feedback submissions from authenticated users without their interaction.

Impact Analysis

If you are a Ghost CMS user running a vulnerable version, attackers could submit fake feedback on your behalf. This could distort user feedback data, damage reputation, or manipulate content metrics. Users must update to version 6.57.1 or later to prevent this.

Mitigation Strategies

Immediately update Ghost to version 6.57.1 or later using Ghost CLI with 'ghost update' or Docker with updated images. Disable the feedback feature temporarily if an update isn't possible. Monitor for unauthorized feedback submissions as a sign of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103285. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart