CVE-2025-40978
12.01.2026, 12:16
Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request to /ticket/x/conversion, using the reply_description parameter.