
CVE-2026-59817 Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation… https://www.cve.org/CVERecord?id=CVE-2026-59817
Post summary
The post reports a CVE-2026-59817 vulnerability in Ghost CMS that allows unauthenticated control of the donation checkout flow, but does not provide a PoC, exploit details, active exploitation evidence, or a patch.

