CVE-2026-107803

CVE-2026-107803 published: ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because `ProcessMaker\Traits\TaskControllerIndexMethods::a...

View full NVD advisory → ← Back to CVE watch