CVE-2025-40977 - Multiple vulnerabilities in WorkDo products

CVE-2025-40977 - Multiple vulnerabilities in WorkDo products

CVE ID : CVE-2025-40977 Published : Jan. 12, 2026, 12:16 p.m. | 14 minutes ago Description : Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a lack of proper validation of user input by sending a POST request to ‘/store-ticket’, using the ‘subject’ and ‘description’ parameters. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Jan. 12, 2026
Impact: XSS

Source: Telegram CVE Monitor