VYPR
Vendor

WorkDo

Products
7
CVEs
7
Across products
8
Status
Private

Products

7

Recent CVEs

7
  • CVE-2025-63294MedNov 4, 2025
    risk 0.42cvss 6.5epss 0.00

    WorkDo HRM SaaS HR and Payroll Tool 8.1 is affected vulnerable to Insecure Permissions. An authenticated user can create leave or resignation records on behalf of other users.

  • CVE-2025-40978MedJan 12, 2026
    risk 0.33cvss —epss 0.00

    Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request to ‘/ticket/x/conversion’, using the ‘reply_description’ parameter.

  • CVE-2025-40977MedJan 12, 2026
    risk 0.33cvss —epss 0.00

    Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a lack of proper validation of user input by sending a POST request to ‘/store-ticket’, using the ‘subject’ and ‘description’ parameters.

  • CVE-2025-40976MedJan 12, 2026
    risk 0.33cvss —epss 0.00

    Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's TicketGo, consisting of a lack of proper validation of user input by sending a POST request to ‘/ticketgo-saas/home’, using the ‘description’ parameter.

  • CVE-2025-40975MedJan 12, 2026
    risk 0.33cvss —epss 0.00

    Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's HRMGo, consisting of a lack of proper validation of user input by sending a POST request to ‘/hrmgo/ticket/changereply’, using the ‘description’ parameter.

  • CVE-2024-9031LowSep 20, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affects some unknown processing of the file /project/task/{task_id}/show. The manipulation of the argument comment leads to cross site scripting. The attack may be…

  • CVE-2024-9030LowSep 20, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown code of the file /deal/{note_id}/note. The manipulation of the argument notes leads to cross site scripting. The attack can be initiated remotely. The exploit has…