ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because `ProcessMaker\Traits\TaskControllerIndexMethods::applyColumnOrdering()` concatenates a user-controlled process_requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.
https://github.com/ProcessMaker/processmaker/security/advisories/GHSA-xf7p-gp7c-w7gh
https://github.com/ProcessMaker/processmaker/releases/tag/v2026.14.3
https://github.com/ProcessMaker/processmaker/pull/9041
https://github.com/ProcessMaker/processmaker/commit/2622b7ae810e02c47157028331c45470567e7b79