CVE-2026-28785
Ghostfolio: Time-Based Blind SQL Injection in Manual Asset Import
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them to read, modify, or delete sensitive financial data for all users in the database. This issue has been patched in version 2.244.0.
| CWE | CWE-89 |
| Vendor | ghostfolio |
| Product | ghostfolio |
| Published | Mar 6, 2026 |
| Last Updated | Mar 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for ghostfolio ghostfolio
Be the first to know when new unknown vulnerabilities affecting ghostfolio ghostfolio are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ghostfolio / ghostfolio
< 2.244.0