CVE-2026-107803 | ProcessMaker up to 2026.14.2 Column Ordering applyColumnOrdering order_by sql injection

SecurityVulns

A vulnerability was found in ProcessMaker up to 2026.14.2 and classified as critical. Affected by this vulnerability is the function ProcessMakerTraitsTaskControllerIndexMethods::applyColumnOrdering of the component Column Ordering. Executing a manipulation of the argument order_by can lead to sql injection.

This vulnerability appears as CVE-2026-107803. The attack may be performed from remote. There is no available exploit.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More