---
id: CVE-2026-107803
title: ProcessMaker is an open source workflow management software suite
summary: >-
  ProcessMaker is an open source workflow management software suite. Prior to
  2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to
  SQL injection through the order_by parameter because
  `ProcessMaker\Traits\TaskContr…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-89
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T18:17:02.487'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107803'
references:
  - url: >-
      https://github.com/ProcessMaker/processmaker/commit/2622b7ae810e02c47157028331c45470567e7b79
    label: security-advisories@github.com
  - url: 'https://github.com/ProcessMaker/processmaker/pull/9041'
    label: security-advisories@github.com
  - url: 'https://github.com/ProcessMaker/processmaker/releases/tag/v2026.14.3'
    label: security-advisories@github.com
  - url: >-
      https://github.com/ProcessMaker/processmaker/security/advisories/GHSA-xf7p-gp7c-w7gh
    label: security-advisories@github.com
tags:
  - nvd
ingestedAt: '2026-10-09T15:00:31.365Z'
---

## Overview

ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because `ProcessMaker\Traits\TaskControllerIndexMethods::applyColumnOrdering()` concatenates a user-controlled process_requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
