CVE-2026-28785

Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them to read, modify, or delete sensitive financial data for all users in the database. This issue has been patched in version 2.244.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ghostfol:ghostfolio:*:*:*:*:*:*:*:*

History

10 Mar 2026, 19:51

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:ghostfol:ghostfolio:*:*:*:*:*:*:*:*
References () https://github.com/ghostfolio/ghostfolio/releases/tag/2.244.0 - () https://github.com/ghostfolio/ghostfolio/releases/tag/2.244.0 - Product, Release Notes
References () https://github.com/ghostfolio/ghostfolio/security/advisories/GHSA-m5cc-7jw5-34xp - () https://github.com/ghostfolio/ghostfolio/security/advisories/GHSA-m5cc-7jw5-34xp - Mitigation, Patch, Vendor Advisory
First Time Ghostfol
Ghostfol ghostfolio

09 Mar 2026, 13:36

Type Values Removed Values Added
Summary
  • (es) Ghostfolio es un software de gestión de patrimonio de código abierto. Antes de la versión 2.244.0, al eludir la validación de símbolos, un atacante puede ejecutar comandos SQL arbitrarios a través del método getHistorical(), lo que podría permitirle leer, modificar o eliminar datos financieros sensibles para todos los usuarios en la base de datos. Este problema ha sido parcheado en la versión 2.244.0.

06 Mar 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-06 05:16

Updated : 2026-03-10 19:51


NVD link : CVE-2026-28785

Mitre link : CVE-2026-28785

CVE.ORG link : CVE-2026-28785


JSON object : View

Products Affected

ghostfol

  • ghostfolio
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')