CVE-2026-107803Medium· 6.5▾ SunlitProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because `ProcessMaker\Traits\TaskContr…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the GET /api/1.0/tasks endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because ProcessMaker\Traits\TaskControllerIndexMethods::applyColumnOrdering() concatenates a user-controlled process_requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-10079High· 7.3A flaw has been found in PHPGurukul Small CRM 4.0
CVE-2025-10405High· 7.3A vulnerability was determined in itsourcecode Baptism Information Management System 1.0
CVE-2025-10479High· 7.3A security flaw has been discovered in SourceCodester Online Student File Management System 1.0
CVE-2025-10387Medium· 6.3A vulnerability was determined in codesiddhant Jasmin Ransomware up to 1.0.1
CVE-2025-10068High· 7.3A flaw has been found in itsourcecode Online Discussion Forum 1.0
CVE-2025-10601High· 7.3A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0