CVE-2026-28443

CRITICAL WAF: High
CVSS 9.8 Published: 2026-03-05
CWE-89

OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint has a SQL injection in the sort.field parameter. This issue has been patched in version 1.20.0.

WAF Coverage Analysis

SQL Injection High WAF Coverage

OWASP: A03:2021 Injection

942xxx - SQL Injection

Affected Software

VendorProductVersion
openreplayopenreplayup to 1.20.0

References

Back to CVE Database