Remote Code Injection Vulnerability in Ghost by TryGhost
CVE-2026-103266
7.1HIGH
What is CVE-2026-103266?
A vulnerability in Ghost versions 5.2.0 through prior to 6.62.0 enables remote attackers to exploit the Stripe Checkout process. This can potentially lead to unauthorized modifications to existing member subscriptions, including changing member names and injecting harmful content into all newsletters sent to that member. The injected content can be rendered based on the recipient's email client, creating avenues for HTML injection or cross-site scripting, severely compromising user data and application security.
Affected Version(s)
Ghost 5.2.0 < 6.62.0
Ghost 6.62.0
