Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Prav33N-Sec

#18871of 53,632
14.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-7327
8.8
2026-02-10
Worklenz · Worklenz · CVE-2026-25947
**Name of the Vulnerable Software and Affected Versions** Worklenz versions prior to 2.1.7 **Description** Worklenz, a project management tool, contains multiple SQL injection flaws in its backend SQL query construction. These flaws affect project and task management controllers, reporting and financial data endpoints, real-time socket.io handlers, and resource allocation and scheduling features. The issue allows for potential unauthorized access and manipulation of data through crafted SQL queries. **Recommendations** Update to version 2.1.7 or later.
PT-2026-7943
5.4
2026-01-22
WordPress · Freeforum · CVE-2026-26188
**Name of the Vulnerable Software and Affected Versions** Solspace Freeform plugin for Craft CMS versions 5.0 through 5.14.6 **Description** A low-privilege authenticated user with form creation/editing permissions can inject arbitrary HTML and JavaScript code into the Craft Control Panel builder and integrations views. Form labels and integration metadata, controlled by the user, are rendered using `dangerouslySetInnerHTML` without proper sanitization, resulting in stored cross-site scripting (XSS). This allows for the execution of malicious scripts when any administrator views the builder or integration screens. **Recommendations** Update to version 5.14.7 or later.