CVE-2026-107803: Processmaker
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because `ProcessMaker\Traits\TaskControllerIndexMethods::applyColumnOrdering()` concatenates a user-controlled process_requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.
Affected products
- Processmaker Processmaker: before 2026.14.3 (fixed in 2026.14.3)
Published 2026-10-09. Last modified 2026-10-09.