The WorklogPRO - Timesheets for Jira plugin in Jira Data Center before version 4.23.6-jira10 and before version 4.23.5-jira9 allows users and attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability. The vulnerability is exploited via a specially crafted payload placed in an issue's summary field
References
Configurations
History
No history.
Information
Published : 2026-01-21 17:16
Updated : 2026-02-02 18:37
NVD link : CVE-2025-57681
Mitre link : CVE-2025-57681
CVE.ORG link : CVE-2025-57681
JSON object : View
Products Affected
thestarware
- worklogpro
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
