CVE-2026-25947

Worklenz is a project management tool. Prior to 2.1.7, there are multiple SQL injection vulnerabilities were discovered in backend SQL query construction affecting project and task management controllers, reporting and financial data endpoints, real-time socket.io handlers, and resource allocation and scheduling features. The vulnerability has been patched in version v2.1.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:worklenz:worklenz:*:*:*:*:*:*:*:*

History

23 Feb 2026, 17:57

Type Values Removed Values Added
Summary
  • (es) Worklenz es una herramienta de gestión de proyectos. Antes de 2.1.7, se descubrieron múltiples vulnerabilidades de inyección SQL en la construcción de consultas SQL del backend que afectaban a los controladores de gestión de proyectos y tareas, a los puntos finales de datos financieros y de informes, a los manejadores de socket.io en tiempo real, y a las características de asignación y programación de recursos. La vulnerabilidad ha sido parcheada en la versión v2.1.7.
CPE cpe:2.3:a:worklenz:worklenz:*:*:*:*:*:*:*:*
First Time Worklenz
Worklenz worklenz
References () https://github.com/Worklenz/worklenz/commit/76e5cb0f5dd566fb65586cd3db30ee951c92a32b - () https://github.com/Worklenz/worklenz/commit/76e5cb0f5dd566fb65586cd3db30ee951c92a32b - Patch
References () https://github.com/Worklenz/worklenz/releases/tag/v2.1.7 - () https://github.com/Worklenz/worklenz/releases/tag/v2.1.7 - Product, Release Notes
References () https://github.com/Worklenz/worklenz/security/advisories/GHSA-f2f8-2ppj-85pf - () https://github.com/Worklenz/worklenz/security/advisories/GHSA-f2f8-2ppj-85pf - Exploit, Mitigation, Patch, Vendor Advisory

10 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 18:16

Updated : 2026-02-23 17:57


NVD link : CVE-2026-25947

Mitre link : CVE-2026-25947

CVE.ORG link : CVE-2026-25947


JSON object : View

Products Affected

worklenz

  • worklenz
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')