SQL Injection Vulnerability in Ghostfolio Wealth Management Software
CVE-2026-28785
9.3CRITICAL
What is CVE-2026-28785?
Ghostfolio, an open-source wealth management software, is susceptible to an SQL injection vulnerability due to improper symbol validation. This flaw allows attackers to bypass validation and execute arbitrary SQL commands using the getHistorical() method. As a result, an attacker could read, modify, or delete sensitive financial data across the database for all users. The issue was addressed in version 2.244.0, and users are urged to update to this version or later to mitigate the risk.
Affected Version(s)
ghostfolio < 2.244.0
