← Back

CVE-2026-25947

nvd nist
Published: Feb 10, 2026Modified: Feb 23, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: security-advisories@github.com (Secondary)

Description

Worklenz is a project management tool. Prior to 2.1.7, there are multiple SQL injection vulnerabilities were discovered in backend SQL query construction affecting project and task management controllers, reporting and financial data endpoints, real-time socket.io handlers, and resource allocation and scheduling features. The vulnerability has been patched in version v2.1.7.

Affected (1)

Products: Worklenz: Worklenz
1 product
Worklenz
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.1.7

References (3)

Source: security-advisories@github.com
ProductRelease Notes
Source: security-advisories@github.com
ExploitMitigationPatchVendor Advisory

Timeline

No history available yet.