« Back to list

Ghostfol

Ghostfolio: vulnerabilities and CVEs

Ghostfolio has 5 published vulnerabilities, 5 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs5
Last 12 months5
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-47127Medium (6.5)0.34%—Aug 7, 2026
Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-URL handler at `GET /api/v1/subscription/stripe/callback?checkoutSessionId=<id>` retrieves the Stripe…
CVE-2026-59708High (8.7)0.59%—Jul 7, 2026
The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private…
CVE-2026-59709Medium (5.3)0.34%—Jul 7, 2026
Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio…
CVE-2026-28785Critical (9.3)0.60%—Mar 6, 2026
Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them…
CVE-2026-28680Critical (9.3)0.35%—Mar 6, 2026
Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing them to exfiltrate sensitive cloud…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application3
  2. T1005 Data from Local System2
  3. T1090 Proxy1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.