CVE-2025-40976 - Multiple vulnerabilities in WorkDo products - Full Analysis

CVE-2025-40976 - Multiple vulnerabilities in WorkDo products - Full Analysis

CVE ID : CVE-2025-40976 Published : Jan. 12, 2026, 12:16 p.m. | 14 minutes ago Description : Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's TicketGo, consisting of a lack of proper validation of user input by sending a POST request to ‘/ticketgo-saas/home’, using the ‘description’ parameter. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Jan. 12, 2026
Impact: XSS

Source: Telegram CVE Monitor