All 5 CVE vulnerabilities found in WorkTime (on-prem/cloud), with AI-generated Chinese analysis, references, and POCs.
Vendor: NesterSoft Inc.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-15563 | Broken Access Control results in Denial of Service in NesterSoft WorkTime CWE-862 | 5.3AI | MediumAI | 2026-02-19 |
| CVE-2025-15562 | Reflected Cross-Site Scripting in NesterSoft WorkTime CWE-79 | 6.1AI | MediumAI | 2026-02-19 |
| CVE-2025-15561 | Local Privilege Escalation in NesterSoft WorkTime CWE-269 | 7.8AI | HighAI | 2026-02-19 |
| CVE-2025-15560 | SQL Injection in NesterSoft WorkTime CWE-89 | 6.5AI | MediumAI | 2026-02-19 |
| CVE-2025-15559 | Unauthenticated OS Command Injection in NesterSoft WorkTime CWE-78 | 9.8AI | CriticalAI | 2026-02-19 |
All 5 known CVE vulnerabilities affecting WorkTime (on-prem/cloud) with full Chinese analysis, references, and POCs where available.