VYPR
Vendor

Ghostfolio

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2026-28785CriMar 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them to read, modify, or delete sensitive financial data for all…

  • CVE-2026-28680CriMar 6, 2026
    risk 0.60cvss 9.3epss 0.00

    Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing them to exfiltrate sensitive cloud metadata (IMDS) or probe internal network services. This issue has…

  • CVE-2026-47127MedAug 7, 2026
    risk 0.35cvss 6.5epss 0.00

    Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-URL handler at `GET /api/v1/subscription/stripe/callback?checkoutSessionId=` retrieves the Stripe Checkout Session by ID and unconditionally grants a Premium…

  • CVE-2026-59708HigJul 7, 2026
    risk 0.00cvss 7.5epss 0.00

    The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retrieve sensitive portfolio information…

  • CVE-2026-59709MedJul 7, 2026
    risk 0.00cvss 4.3epss 0.00

    Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with valid read-only share tokens can…