Upwork's vulnerability profile centers on its time-tracking application, a focused product footprint typical of a platform vendor rather than a broad infrastructure provider. The durable signal is concentrated in code-integrity weaknesses affecting the tracker, where the download and execution of software components without sufficient validation creates an avenue for tampering; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Upwork over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12162HIGH Upwork Time Tracker 5.2.2.716 doesn't verify the SHA256 hash of the downloaded program update before running it, which could lead to code execution or local privilege escalation by | Jul 23, 2019 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Upwork.
Media articles that mention a CVE ID that affects a product developed by Upwork — matched by CVE ID, not by vendor name.