CVE-2026-25947

Worklenz is a project management tool. Prior to 2.1.7, there are multiple SQL injection vulnerabilities were discovered in backend SQL query construction affecting project and task management controllers, reporting and financial data endpoints, real-time socket.io handlers, and resource allocation and scheduling features. The vulnerability has been patched in version v2.1.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:worklenz:worklenz:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-10 18:16

Updated : 2026-06-17 10:25


NVD link : CVE-2026-25947

Mitre link : CVE-2026-25947

CVE.ORG link : CVE-2026-25947


JSON object : View

Products Affected

worklenz

  • worklenz
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')