CVE-2026-107803
ProcessMaker has SQL injection in the tasks endpoint through the order_by parameter
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because `ProcessMaker\Traits\TaskControllerIndexMethods::applyColumnOrdering()` concatenates a user-controlled process_requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.
| CWE | CWE-89 |
| Vendor | processmaker |
| Product | processmaker |
| Published | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for processmaker processmaker
Be the first to know when new medium vulnerabilities affecting processmaker processmaker are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
ProcessMaker / processmaker
< 2026.14.3
References
github.com: https://github.com/ProcessMaker/processmaker/security/advisories/GHSA-xf7p-gp7c-w7gh github.com: https://github.com/ProcessMaker/processmaker/pull/9041 github.com: https://github.com/ProcessMaker/processmaker/commit/2622b7ae810e02c47157028331c45470567e7b79 github.com: https://github.com/ProcessMaker/processmaker/releases/tag/v2026.14.3