Worksuite · Hr · CVE-2026-4165
**Name of the Vulnerable Software and Affected Versions**
Worksuite HR, CRM and Project Management versions up to 5.5.25
**Description**
A security issue exists in Worksuite HR, CRM and Project Management. The issue involves cross site scripting, triggered by manipulating the `Client Note` argument within an unknown function of the file '/account/orders/create'. This attack can be initiated remotely. The exploit has been publicly disclosed.
**Recommendations**
Versions prior to 5.5.25 should be updated. As a temporary workaround, consider restricting or disabling access to the file '/account/orders/create' until a patch is available.