{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ghost-4.39.0--version--6.64.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-103266"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ghost (5.2.0 - 6.61.9)","Ghost (\u003c 6.62.0)","Ghost (2.10.0 - 6.62.x)","Ghost (5.8.0 - 6.33.9)","Ghost (0.5.3 - \u003c 6.50.0)","Ghost (6.22.1 \u003c= version \u003c 6.64.0)","Ghost (6.10.3 to \u003c 6.64.0)","Ghost (4.39.0 \u003c= version \u003c 6.64.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xss","application-security","enumeration","api-security","remote-code-execution","ghost","vulnerability","cms"],"_cs_type":"threat","_cs_vendors":["Ghost"],"content_html":"\u003cp\u003eGhost versions 5.2.0 through 6.61.9 are susceptible to an unauthenticated vulnerability within the Stripe Checkout integration. An attacker can exploit this flaw to force an arbitrary paid subscription onto an existing member's account. This process allows the attacker to manipulate the member's profile, specifically the name field. Furthermore, the vulnerability enables the injection of malicious content, which is subsequently embedded into newsletters generated and distributed by the platform to the affected member. Depending on the email client's handling of the injected HTML, this can lead to successful HTML injection or Cross-Site Scripting (XSS) attacks. Defenders should prioritize patching, as this vulnerability allows for unauthorized modification of member data and potential delivery of malicious payloads via trusted communication channels.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to the integrity of member databases and the security of end-user communications. Successful exploitation allows attackers to associate paid subscriptions with arbitrary users and deliver malicious scripts directly to user email inboxes. This can lead to account takeover, theft of user credentials, or malicious redirects when victims interact with the injected content within the newsletter.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Ghost to version 6.62.0 or later to remediate CVE-2026-103266.\u003c/li\u003e\n\u003cli\u003eAudit recent member subscription history and newsletter delivery logs for anomalies associated with unauthorized Stripe checkout activity.\u003c/li\u003e\n\u003cli\u003eImplement stricter input validation on member profile name fields to mitigate the potential impact of HTML and script injection during the patching window.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T14:24:38Z","date_published":"2026-10-01T12:42:24Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ghost-stripe-vuln/","summary":"A vulnerability in Ghost versions 5.2.0 through 6.61.9 allows unauthenticated remote attackers to manipulate Stripe Checkout flows to modify member records and inject malicious content into newsletters.","title":"Unauthenticated Stripe Checkout Manipulation in Ghost","url":"https://feed.craftedsignal.io/briefs/2026-10-ghost-stripe-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Ghost (4.39.0 \u003c= Version \u003c 6.64.0)","version":"https://jsonfeed.org/version/1.1"}