CVE-2025-57681

The WorklogPRO - Timesheets for Jira plugin in Jira Data Center before version 4.23.6-jira10 and before version 4.23.5-jira9 allows users and attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability. The vulnerability is exploited via a specially crafted payload placed in an issue's summary field
Configurations

Configuration 1 (hide)

cpe:2.3:a:thestarware:worklogpro:*:*:*:*:*:jira:*:*

History

02 Feb 2026, 18:37

Type Values Removed Values Added
CPE cpe:2.3:a:thestarware:worklogpro:*:*:*:*:*:jira:*:*
First Time Thestarware
Thestarware worklogpro
References () https://marketplace.atlassian.com/apps/1212626/worklogpro-timesheets-for-jira/version-history - () https://marketplace.atlassian.com/apps/1212626/worklogpro-timesheets-for-jira/version-history - Product
References () https://thestarware.atlassian.net/wiki/spaces/WLP/pages/3326574597/Security+Advisory+CVE-2025-57681+-+Stored+XSS+in+WorklogPRO+DC - () https://thestarware.atlassian.net/wiki/spaces/WLP/pages/3326574597/Security+Advisory+CVE-2025-57681+-+Stored+XSS+in+WorklogPRO+DC - Exploit, Vendor Advisory

21 Jan 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-21 17:16

Updated : 2026-02-02 18:37


NVD link : CVE-2025-57681

Mitre link : CVE-2025-57681

CVE.ORG link : CVE-2025-57681


JSON object : View

Products Affected

thestarware

  • worklogpro
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')