CVE-2025-70368

Worklenz version 2.1.5 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Project Updates feature. An attacker can submit a malicious payload in the Updates text field which is then rendered in the reporting view without proper sanitization. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:worklenz:worklenz:2.1.5:*:*:*:*:*:*:*

History

17 Jun 2026, 10:03

Type Values Removed Values Added
Summary
  • (es) La versión 2.1.5 de Worklenz contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en la función de Actualizaciones de Proyecto. Un atacante puede enviar una carga útil maliciosa en el campo de texto de Actualizaciones que luego se renderiza en la vista de informes sin la sanitización adecuada. JavaScript malicioso puede ejecutarse en el navegador de una víctima cuando navegan a la página que contiene el campo vulnerable.

13 Feb 2026, 15:12

Type Values Removed Values Added
First Time Worklenz
Worklenz worklenz
References () https://github.com/Stolichnayer/CVE-2025-70368 - () https://github.com/Stolichnayer/CVE-2025-70368 - Exploit, Third Party Advisory
References () https://github.com/Worklenz/worklenz - () https://github.com/Worklenz/worklenz - Product
CPE cpe:2.3:a:worklenz:worklenz:2.1.5:*:*:*:*:*:*:*

27 Jan 2026, 20:16

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
References () https://github.com/Stolichnayer/CVE-2025-70368 - () https://github.com/Stolichnayer/CVE-2025-70368 -

26 Jan 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-26 19:16

Updated : 2026-06-17 10:03


NVD link : CVE-2025-70368

Mitre link : CVE-2025-70368

CVE.ORG link : CVE-2025-70368


JSON object : View

Products Affected

worklenz

  • worklenz
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')