CVE-2026-28785 | Ghostfolio up to 2.243.x getHistorical sql injection (GHSA-m5cc-7jw5-34xp)
A vulnerability categorized as critical has been discovered in Ghostfolio up to 2.243.x. This vulnerability affects the function getHistorical. The manipulation results in sql injection.
This vulnerability was named CVE-2026-28785. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.