PT-2026-3781 · Thestarware · Worklogpro

Published

2026-01-21

·

Updated

2026-02-02

·

CVE-2025-57681

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WorklogPRO - Timesheets for Jira versions prior to 4.23.6-jira10 WorklogPRO - Timesheets for Jira versions prior to 4.23.5-jira9
Description The WorklogPRO - Timesheets for Jira plugin contains a flaw that allows the injection of arbitrary HTML or JavaScript code. This is a Cross-Site Scripting (XSS) issue, where a malicious payload placed within an issue's summary field can be exploited. The vulnerability can be leveraged by both users and attackers. The vulnerable parameter is the summary field.
Recommendations Upgrade WorklogPRO - Timesheets for Jira to version 4.23.6-jira10 or later. Upgrade WorklogPRO - Timesheets for Jira to version 4.23.5-jira9 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-57681

Affected Products

Worklogpro