The WorklogPRO - Timesheets for Jira plugin in Jira Data Center before version 4.23.6-jira10 and before version 4.23.5-jira9 allows users and attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability. The vulnerability is exploited via a specially crafted payload placed in an issue's summary field
References
Configurations
History
02 Feb 2026, 18:37
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:thestarware:worklogpro:*:*:*:*:*:jira:*:* | |
| First Time |
Thestarware
Thestarware worklogpro |
|
| References | () https://marketplace.atlassian.com/apps/1212626/worklogpro-timesheets-for-jira/version-history - Product | |
| References | () https://thestarware.atlassian.net/wiki/spaces/WLP/pages/3326574597/Security+Advisory+CVE-2025-57681+-+Stored+XSS+in+WorklogPRO+DC - Exploit, Vendor Advisory |
21 Jan 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-21 17:16
Updated : 2026-02-02 18:37
NVD link : CVE-2025-57681
Mitre link : CVE-2025-57681
CVE.ORG link : CVE-2025-57681
JSON object : View
Products Affected
thestarware
- worklogpro
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
