SQL Injection Vulnerability in Ghostfolio Wealth Management Software
CVE-2026-28785

9.3CRITICAL

Key Information:

Vendor

Ghostfolio

Vendor
CVE Published:
6 March 2026

What is CVE-2026-28785?

Ghostfolio, an open-source wealth management software, is susceptible to an SQL injection vulnerability due to improper symbol validation. This flaw allows attackers to bypass validation and execute arbitrary SQL commands using the getHistorical() method. As a result, an attacker could read, modify, or delete sensitive financial data across the database for all users. The issue was addressed in version 2.244.0, and users are urged to update to this version or later to mitigate the risk.

Affected Version(s)

ghostfolio < 2.244.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.