PT-2026-7327 · Worklenz · Worklenz

Prav33N-Sec

·

Published

2026-02-10

·

Updated

2026-02-10

·

CVE-2026-25947

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Worklenz versions prior to 2.1.7
Description Worklenz, a project management tool, contains multiple SQL injection flaws in its backend SQL query construction. These flaws affect project and task management controllers, reporting and financial data endpoints, real-time socket.io handlers, and resource allocation and scheduling features. The issue allows for potential unauthorized access and manipulation of data through crafted SQL queries.
Recommendations Update to version 2.1.7 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25947
GHSA-F2F8-2PPJ-85PF

Affected Products

Worklenz