CVE-2026-105680Medium· 6.5▾ SunlitGhost is a Node.js content management system. From 5.81.0 until 6.60.0, staff with the Author role could delete posts and pages that they did not author. This issue is fixed in version 6.60.0.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Ghost is a Node.js content management system. From 5.81.0 until 6.60.0, staff with the Author role could delete posts and pages that they did not author. This issue is fixed in version 6.60.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103274Medium· 5.3Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode
CVE-2026-103268High· 8.8Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset
CVE-2026-103269Medium· 5.3Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an authenticated site member to read the excerpts of posts they do not have access to (gated content).
CVE-2026-105682Low· 2.7Ghost is a Node.js content management system
CVE-2026-105683Low· 3.8Ghost is a Node.js content management system
CVE-2026-105679High· 7.3Ghost is a Node.js content management system