ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the GET /api/1.0/tasks endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because ProcessMaker\Traits\TaskControllerIndexMethods::applyColumnOrdering() concatenates a user-controlled process_requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.