PT-2026-4804 · Worklenz · Worklenz

CVE-2025-70368

·

Published

2026-01-26

·

Updated

2026-02-13

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Worklenz version 2.1.5
Description Worklenz version 2.1.5 has a Stored Cross-Site Scripting (XSS) issue in the Project Updates feature. An attacker can inject a malicious payload into the Updates text field. This payload is then displayed in the reporting view without sufficient sanitization, potentially leading to the execution of malicious JavaScript in a victim’s browser when they access the page with the vulnerable field.
Recommendations Apply updates to resolve the issue. As a temporary workaround, consider sanitizing all user inputs in the Updates text field to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-70368

Affected Products

Worklenz