VYPR

Worklenz

by Worklenz

Source repositories

CVEs (4)

  • CVE-2026-85388HigSep 3, 2026
    risk 0.46cvss 8.1epss 0.00

    Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolean-based blind SQL injection…

  • CVE-2026-85389MedSep 3, 2026
    risk 0.35cvss 6.5epss 0.00

    Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task data. Attackers can query task endpoints with arbitrary task UUIDs to retrieve work logs, comments,…

  • CVE-2025-70368MedJan 26, 2026
    risk 0.35cvss 5.4epss 0.00

    Worklenz version 2.1.5 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Project Updates feature. An attacker can submit a malicious payload in the Updates text field which is then rendered in the reporting view without proper sanitization. Malicious JavaScript…

  • CVE-2026-25947HigFeb 10, 2026
    risk 0.00cvss 8.8epss 0.01

    Worklenz is a project management tool. Prior to 2.1.7, there are multiple SQL injection vulnerabilities were discovered in backend SQL query construction affecting project and task management controllers, reporting and financial data endpoints, real-time socket.io handlers, and…