{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-27T04:25:42.289","vulnerabilities":[{"cve":{"id":"CVE-2026-25947","sourceIdentifier":"security-advisories@github.com","published":"2026-02-10T18:16:38.423","lastModified":"2026-06-17T10:25:28.417","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Worklenz is a project management tool. Prior to 2.1.7, there are multiple SQL injection vulnerabilities were discovered in backend SQL query construction affecting project and task management controllers, reporting and financial data endpoints, real-time socket.io handlers, and resource allocation and scheduling features. The vulnerability has been patched in version v2.1.7."},{"lang":"es","value":"Worklenz es una herramienta de gestión de proyectos. Antes de 2.1.7, se descubrieron múltiples vulnerabilidades de inyección SQL en la construcción de consultas SQL del backend que afectaban a los controladores de gestión de proyectos y tareas, a los puntos finales de datos financieros y de informes, a los manejadores de socket.io en tiempo real, y a las características de asignación y programación de recursos. La vulnerabilidad ha sido parcheada en la versión v2.1.7."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"Worklenz","product":"worklenz","versions":[{"version":"< 2.1.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-10T19:26:10.012909Z","id":"CVE-2026-25947","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:worklenz:worklenz:*:*:*:*:*:*:*:*","versionEndExcluding":"2.1.7","matchCriteriaId":"C488A1A0-AD25-4AF0-B022-3F30C5F88BEC"}]}]}],"references":[{"url":"https://github.com/Worklenz/worklenz/commit/76e5cb0f5dd566fb65586cd3db30ee951c92a32b","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/Worklenz/worklenz/releases/tag/v2.1.7","source":"security-advisories@github.com","tags":["Product","Release Notes"]},{"url":"https://github.com/Worklenz/worklenz/security/advisories/GHSA-f2f8-2ppj-85pf","source":"security-advisories@github.com","tags":["Exploit","Mitigation","Patch","Vendor Advisory"]}]}}]}