OpenTrade before 2019-11-23 allows SQL injection, related to server/modules/api/v1.js and server/utils.js.
[ { "events": [ { "introduced": "0" }, { "fixed": "2019-11-23" } ] }, { "events": [ { "introduced": "0" }, { "fixed": "2019-11-23" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19250.json"