CVE-2026-103278 - Ghost 5.8.0 before 6.34.0 Staff Account Takeover via Admin iframe
CVE ID :CVE-2026-103278 Published : Oct. 1, 2026, 11:17 a.m. | 2 hours ago Description :Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff user accounts. Attackers with content publishing privileges can...