Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-70368 — Worklenz version 2.1.5 Stored Cross-Site Scripting (XSS) | Kitploit
Tools/GitHubGitHub/stolichnayer/cve-2025-70368
Vulnerability AnalysisWeb Application ExploitationWeb SecurityPenetration TestingLearning & Education
GitHubstolichnayer/cve-2025-70368

CVE-2025-70368

Worklenz version 2.1.5 Stored Cross-Site Scripting (XSS)

View Repository
17 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-70368

Stored Cross-Site Scripting (XSS) in Project Updates Feature

Worklenz Logo

Worklenz

All in one project management tool for efficient teams

📜 Description

Worklenz version 2.1.5 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Project Updates feature. An attacker can submit a malicious payload in the Updates text field which is then rendered in the reporting view without proper sanitization. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field.

🔍 Affected Versions

StatusVersion
🔴 Vulnerable2.1.5

🛠️ Steps to Reproduce

1️⃣ Navigate to Projects → "Project Name" → Updates

2️⃣ Enter the following payload:

root@kitploit:~

3️⃣ Navigate to Reporting → Projects

4️⃣ The stored payload is rendered, and the alert executes:

⚠️ Disclaimer

This project is intended for educational and ethical research purposes only. Unauthorized testing on systems without explicit permission is illegal. Use responsibly and only on systems you own or have permission to test.

🧑‍💻 Discovery

This vulnerability was discovered by Alex Perrakis (Stolichnayer).

🔗 References:

  • Worklenzs Github Repository
Download Tool