Description
Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription to an existing member, modify that member's name, and inject content into newsletters sent to the member. Depending on the recipient's email client, the injected content may be rendered, resulting in HTML injection or cross-site scripting (XSS).
Published: 2026-10-01
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting and unauthorized subscription modification.
Action: Patch
AI Analysis

Impact

Ghost versions 5.2.0 through prior releases 6.61.9 allow an attacker who has no user credentials to exploit the Stripe Checkout flow. By doing so, the attacker can attach a paid subscription to an existing member, alter the member's display name, and inject arbitrary HTML into newsletters sent to that member. If the member's email client renders the injected content, the user may experience cross‑site scripting or HTML injection, enabling malicious payload delivery.

Affected Systems

TryGhost’s Ghost CMS, specifically versions 5.2.0 up to but not including 6.62.0, are affected. Any deployment of these releases that rely on Stripe Checkout for subscription management is at risk.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate‑to‑high severity, while no EPSS data is available and the vulnerability is not in the CISA KEV catalog. Attackers need only send a crafted Stripe Checkout request, an action that can be performed without authentication. If the targeted Ghost installation permits the flow, the exploit can lead to unintended subscription charges, user data tampering, and exposure of malicious content to subscribers. The lack of authentication requirement, combined with the ability to inject HTML into newsletters, increases the likelihood that the vulnerability can be leveraged in an active attack.

Generated by OpenCVE AI on October 1, 2026 at 14:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.62.0 or later, following the vendor’s published fix.
  • If an immediate upgrade is not possible, restrict access to the Stripe Checkout endpoint to authenticated users only or implement network‑level filtering to block unauthenticated requests.
  • Validate and sanitize all input received through the Stripe Checkout flow so that injected HTML cannot be included in newsletters; consider rendering newsletters with strict encoding or stripping of dangerous markup.
  • Monitor logs for unexpected subscription creations and review newsletter content for suspicious injected content, responding quickly to any signs of exploitation.

Generated by OpenCVE AI on October 1, 2026 at 14:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription to an existing member, modify that member's name, and inject content into newsletters sent to the member. Depending on the recipient's email client, the injected content may be rendered, resulting in HTML injection or cross-site scripting (XSS).
Title Ghost 5.2.0 before 6.62.0 Unauthenticated Stripe Checkout Account Modification
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-863
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T10:42:07.674Z

Reserved: 2026-09-30T10:58:33.573Z

Link: CVE-2026-103266

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:21.737

Modified: 2026-10-01T15:06:17.330

Link: CVE-2026-103266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:15:09Z

Weaknesses