CVE-2026-59817 MEDIUM

CVE-2026-59817: Ghost: Paid gift memberships obtainable at minimal cost via the donations feature

Vendor Tryghost
Product Ghost
Weakness CWE-472
Published July 9, 2026
Last update July 14, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing money from a site or its members. This issue is fixed in version 6.44.0.

Key dates

02Disclosure timeline

July 9, 2026 CVE published
July 14, 2026 Record updated

Related vulnerabilities

04Related CVE