CVE-2026-103288: Tryghost Ghost

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment engagement data.

Affected products

  • Tryghost Ghost: from 5.9.0, before 6.44.1 (fixed in 6.44.1)

Published 2026-10-01. Last modified 2026-10-01.