Ghost from version 0.8.0 before 6.23.0 contains an information disclosure vulnerability in its setup endpoint: the endpoint responds to unauthenticated requests with the site owner's email address, allowing any remote visitor to obtain it.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-201"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103280.json"
}