OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103266

HIGH · CVSS 7.1 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Versions 5.2.0 through 6.61.0 of Ghost are vulnerable to exploitation by remote attackers who can manipulate the Stripe Checkout flow, allowing them to attach paid subscriptions to existing members, alter member names, and inject content into newsletters. This could lead to HTML injection or cross-site scripting (XSS) vulnerabilities, potentially compromising user data and security. Organizations using affected Ghost versions should prioritize patching to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103266
Severity
HIGH
CVSS
7.1
EPSS
0.30%

Original NVD Description

Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription to an existing member, modify that member's name, and inject content into newsletters sent to the member. Depending on the recipient's email client, the injected content may be rendered, resulting in HTML injection or cross-site scripting (XSS).