VYPR

Worksuite

by Worksuite

CVEs (2)

  • CVE-2026-18741MedAug 13, 2026
    risk 0.31cvss 4.8epss 0.00

    Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site scripting vulnerability in the Asset Management module that allows authenticated administrators to inject arbitrary JavaScript by entering malicious payloads into the Location and Description fields when…

  • CVE-2026-4165LowMar 16, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability has been found in Worksuite HR, CRM and Project Management up to 5.5.25. The affected element is an unknown function of the file /account/orders/create. The manipulation of the argument Client Note leads to cross site scripting. The attack can be initiated…