CVE-2026-59817
Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated at
CVSS
5.3
Medio
EPSS
0.3%
p17
KEV
—
Exploit Today
5
0-100
Publicado: 9 jul 2026 · Última mod.: 14 jul 2026 · CWE-472 · CWE-639
0.3%EPSS · 30 días0.3%
2026-07-102026-07-20
Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing money from a site or its members. This issue is fixed in version 6.44.0.
- github.comhttps://github.com/TryGhost/Ghost/commit/cab716cd015ac04b7ee50c7a405478d97bc7b1e0
- github.comhttps://github.com/TryGhost/Ghost/commit/ee7b991b466a7849c70f9d1caed8e491ee4113c6
- github.comhttps://github.com/TryGhost/Ghost/pull/28351
- github.comhttps://github.com/TryGhost/Ghost/pull/28352
- github.comhttps://github.com/TryGhost/Ghost/security/advisories/GHSA-xm43-3m56-w3wf
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-552558.4 ALT42.9%
KEV—63Langflow Authorization Bypass Through User-Controlled Key Vulnerability13dCVE-2021-464168.1 ALT89.9%
——27Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.8dCVE-2022-289867.5 ALT80.9%
——24LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.12dCVE-2026-393647.5 ALT79.6%
——24Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.6dCVE-2024-220495.3 MED67.0%
——20httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.6dCVE-2020-234465.3 MED65.5%
——20Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API12d