Ghostfol develops Ghostfolio, a personal wealth-management and portfolio-tracking application, with its observed vulnerability exposure centered on server-side input handling and request validation—specifically SQL injection and server-side request forgery weaknesses. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ghostfol over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-28785CRITICAL Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistori | Mar 6, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-28680CRITICAL Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing the | Mar 6, 2026 | 9.3 | 31 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ghostfol.
Media articles that mention a CVE ID that affects a product developed by Ghostfol — matched by CVE ID, not by vendor name.