CVE-2026-47127 | Ghostfolio up to 3.3.x Stripe Checkout Success URL callback checkoutSessionId privileges management
A vulnerability was found in Ghostfolio up to 3.3.x. It has been classified as problematic. Affected is an unknown function of the file /api/v1/subscription/stripe/callback of the component Stripe Checkout Success URL Handler. This manipulation of the argument checkoutSessionId causes improper privilege management.
This vulnerability appears as CVE-2026-47127. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More