PT-2026-23647 · Unknown · Ghostfolio

Ratrarity

·

Published

2026-03-06

·

Updated

2026-03-11

·

CVE-2026-28785

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghostfolio versions prior to 2.244.0
Description Ghostfolio is a wealth management software susceptible to arbitrary SQL command execution. An attacker can bypass symbol validation to execute SQL commands through the getHistorical() method. Successful exploitation could allow an attacker to read, modify, or delete sensitive financial data for all users in the database.
Recommendations Update to version 2.244.0 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-28785
GHSA-M5CC-7JW5-34XP

Affected Products

Ghostfolio