Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing money from a site or its members. This issue is fixed in version 6.44.0.
References
Configurations
No configuration.
History
09 Jul 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-09 18:16
Updated : 2026-07-14 02:16
NVD link : CVE-2026-59817
Mitre link : CVE-2026-59817
CVE.ORG link : CVE-2026-59817
JSON object : View
Products Affected
No product.
