Skip to content
Vulnerability intelligence

CVE-2026-103266: Ghost inject newsletter content

CVE-2026-103266 turns a payment step into a route to a publisher's subscribers. Ghost 6.62.0 is the fixed version.

2026