PT-2026-56900 · Ghost · Ghost

CVE-2026-59817

·

Published

2026-07-09

·

Updated

2026-08-04

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ghost versions 6.27.0 through 6.43.x
Description The public donation checkout flow in this Node.js content management system allows an unauthenticated attacker to manipulate donation checkout metadata. This can lead to the acquisition of full paid gift memberships for a minimal payment. This issue does not expose customer or member data, nor does it allow for the theft of funds from the site or its members.
Recommendations Update to version 6.44.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GHOST-2026-59817
CVE-2026-59817
GHSA-XM43-3M56-W3WF

Affected Products

Ghost