Update: CVE-2025-40978 - Multiple vulnerabilities in WorkDo products

Update: CVE-2025-40978 - Multiple vulnerabilities in WorkDo products

CVE ID : CVE-2025-40978 Published : Jan. 12, 2026, 12:16 p.m. | 14 minutes ago Description : Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request to ‘/ticket/x/conversion’, using the ‘reply_description’ parameter. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Jan. 12, 2026
Impact: XSS

Source: Telegram CVE Monitor