- NVD lists CVE-2026-103266: in Ghost 5.2.0 up to 6.62.0, an unauthenticated attacker can abuse Stripe Checkout to alter members and inject newsletter content.
- The damage is mostly to integrity: what members see and what is attached to their accounts. The CVSS 3.1 score is 7.1 (High).
- Check whether your Ghost sites run a version before 6.62.0, and review member and subscription records for changes you did not make.
A publisher's payment page is usually treated as plumbing. A newly listed flaw in Ghost shows why that is a mistake. The checkout step connects to member accounts, and member accounts connect to the newsletter inbox.
What the record says
The NIST National Vulnerability Database published CVE-2026-103266 on October 1, 2026. It covers Ghost versions from 5.2.0 up to, but not including, 6.62.0.
According to the record, a remote attacker without authentication can abuse the Stripe Checkout flow. That is the payment step tied to paid subscriptions. Through it, the attacker can do three things to a member who already exists.
The attacker can tie a paid plan to that member's account. The attacker can also rewrite the member's name. And the attacker can place content of their own choosing into the newsletters that member receives.
The record adds a condition. Whether that planted content actually takes effect depends on the reader's email software. Where it does, the result can be HTML injection or cross-site scripting (XSS). In plain words, XSS means attacker-supplied code runs inside content the reader trusts.
Why the score points at trust, not theft
The score comes from VulnCheck, which listed it as the scorer. It is 7.1 (High) under both CVSS 3.1 and CVSS 4.0.
The vector shows where the harm falls. Network access is enough, complexity is low, and no privileges are needed. Confidentiality impact is rated low. Integrity impact is rated high.
In plain terms, the flaw is rated as more about changing things than reading them. The things changed are who a member is, what they pay for, and what their newsletter says.
The vector also marks user interaction as required. The record does not say what that interaction is. Do not assume it makes the flaw hard to use.
The lesson: the billing flow is part of the publishing surface
This shows a pattern in how publishing systems are built. Payments, identity and email delivery are separate features on a roadmap. To an attacker, they are one chain. A weakness in the first link can reach the last one.
The people at the end of that chain are the members. They are readers who chose to sign up and trust the sender. Content that appears in a message from a publisher they know carries that publisher's credibility.
The record does not report exploitation in the wild. It does not describe a fix beyond the version boundary, and it does not say how many sites are affected. Those details may be in the references NVD lists: a GitHub security advisory from the Ghost project and a VulnCheck advisory.
Questions to put to your team
Ask which Ghost versions you run, including staging sites and ones an agency manages. Anything from 5.2.0 up to but not including 6.62.0 falls in the listed range.
Ask who owns the upgrade, and by when. Read the Ghost advisory (GHSA-qppx-rw6v-xjqf) before setting the timeline.
Ask whether anyone has checked member records for subscriptions or name changes nobody can explain. The record does not say such changes leave a trace, so treat the check as a way to find out.
Ask who reviews newsletter content before it goes out, and whether that review would catch markup that renders differently in different email clients.
A newsletter is a promise that the sender controls what arrives. When a checkout page can alter that, the payment flow needs the same patch discipline as the login page.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: NIST NVD.





