CRAC Learning - Tech@cracbotDisclosure
The post confirms a high‑severity CVE (CVE‑2026‑28680) affecting Ghostfolio versions prior to 2.245.0, noting its critical CVSS score but not providing exploit details or patches.
CVE@CVEnewDisclosure
The tweet reports an SSRF vulnerability in Ghostfolio’s manual asset import prior to version 2.245.0, highlighting the feature and type of attack.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces a Server‑Side Request Forgery vulnerability in Ghostfolio affecting versions before 2.245.0 but does not provide PoC, exploit, or mitigation details.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces CVE‑2026‑28680, a critical SSRF flaw in Ghostfolio’s manual asset import, but provides no PoC, exploit, active‑exploitation evidence, or patch details.
CVEFind.com@CveFindComPatch
The notice alerts users to a critical SSRF vulnerability in Ghostfolio versions prior to 2.245.0 and recommends updating to that patch version.