CVE-2026-28443
EUVD-2026-988005.03.2026, 21:16
OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint has a SQL injection in the sort.field parameter. This issue has been patched in version 1.20.0.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openreplay | openreplay | 𝑥 < 1.20.0 |
𝑥
= Vulnerable software versions