CVE-2026-28443 | OpenReplay up to 1.19.x search sort.field sql injection (GHSA-q6gf-3qg3-pww5)
A vulnerability classified as critical has been found in OpenReplay up to 1.19.x. Impacted is an unknown function of the file /{projectId}/cards/search. Performing a manipulation of the argument sort.field results in sql injection.
This vulnerability is cataloged as CVE-2026-28443. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.