📦 Worktime

by Nestersoft

🔍 What is Worktime?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-15559

CRITICAL CVSS 9.8 Feb 19, 2026

CVE-2025-15559 is an unauthenticated OS command injection vulnerability in NesterSoft WorkTime server's client generation API. Attackers can execute arbitrary commands with SYSTEM privileges by manipu...

CVE-2025-15561

HIGH CVSS 7.8 Feb 19, 2026

This vulnerability allows local attackers to achieve privilege escalation to SYSTEM level by placing a malicious executable in a world-writable directory. The WorkTime monitoring daemon will automatic...

CVE-2025-15563

MEDIUM CVSS 5.3 Feb 19, 2026

This vulnerability allows any unauthenticated user to reset the WorkTime on-prem database configuration by sending a specific HTTP request to the WorkTime server. This occurs because no authorization ...