CVE-2026-107803 | ProcessMaker up to 2026.14.2 Column Ordering applyColumnOrdering order_by sql injection
A vulnerability was found in ProcessMaker up to 2026.14.2 and classified as critical. Affected by this vulnerability is the function ProcessMakerTraitsTaskControllerIndexMethods::applyColumnOrdering of the component Column Ordering. Executing a manipulation of the argument order_by can lead to sql injection.
This vulnerability appears as CVE-2026-107803. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More