8.7
CVE-2025-41004 - Multiple vulnerabilities in Imaster products Open configuration options
Imaster's Patient Records Management System is vulnerable to SQL Injection in the endpoint ‘/projects/hospital/admin/complaints.php’ through the ‘id’ parameter.
5.1
CVE-2025-41003 - Multiple vulnerabilities in Imaster products Open configuration options
Imaster's Patient Record Management System contains a stored Cross-Site Scripting (XSS) vulnerability in the endpoint ‘/projects/hospital/admin/edit_patient.php’. By injecting a malicious script into the ‘firstname’ parameter, the JavaScript code is stored and executed every time a user accesses th…
5.1
CVE-2025-40978 - Multiple vulnerabilities in WorkDo products
Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request to ‘/ticket/x/conversion’, using the ‘reply_description’ parameter.
5.1
CVE-2025-40977 - Multiple vulnerabilities in WorkDo products
Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a lack of proper validation of user input by sending a POST request to ‘/store-ticket’, using the ‘subject’ and ‘description’ parameters.
5.1
CVE-2025-40976 - Multiple vulnerabilities in WorkDo products
Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's TicketGo, consisting of a lack of proper validation of user input by sending a POST request to ‘/ticketgo-saas/home’, using the ‘description’ parameter.
5.1
CVE-2025-40975 - Multiple vulnerabilities in WorkDo products
Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's HRMGo, consisting of a lack of proper validation of user input by sending a POST request to ‘/hrmgo/ticket/changereply’, using the ‘description’ parameter.
0.0
CVE-2026-22837 -
Not used
0.0
CVE-2026-22834 -
Not used
0.0
CVE-2026-22835 -
Not used
0.0
CVE-2026-22833 -
Not used