Unrated severityNVD Advisory· Published Jan 21, 2026· Updated Jan 21, 2026
CVE-2025-57681
CVE-2025-57681
Description
The WorklogPRO - Timesheets for Jira plugin in Jira Data Center before version 4.23.6-jira10 and before version 4.23.5-jira9 allows users and attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability. The vulnerability is exploited via a specially crafted payload placed in an issue's summary field
Affected products
1- Range: <4.23.6-jira10, <4.23.5-jira9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.