VulnSea

HelpDesk vulnerabilities

CVEs whose affected-version data names the HelpDesk package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-23756Medium· 5.4
5mo ago

GFI HelpDesk < 4.99.9 Stored XSS via Troubleshooter Step Subject

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Controller_Step.InsertSubmit() and EditSubmit() before being rendered by Vi…

▾ SunlitGFI Software · HelpDeskEPSS 0.14%via CVEORG
CVE-2026-23753Medium· 4.8
5mo ago

GFI HelpDesk < 4.99.9 Stored XSS via charset Parameter

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality where the charset POST parameter is passed directly to SWIFT_Language::Create() without HTML sanitization and subseq…

▾ SunlitGFI Software · HelpDeskEPSS 0.15%via CVEORG
CVE-2026-23758Medium· 5.1
5mo ago

GFI HelpDesk < 4.99.9 Stored XSS via editsubject Parameter

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the editsubject POST parameter. Attackers …

▾ SunlitGFI Software · HelpDeskEPSS 0.15%via CVEORG
CVE-2026-23757Medium· 5.4
5mo ago

GFI HelpDesk < 4.99.10 Stored XSS via Reports Module

GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly to SWIFT_Report::Create() without HTML sanitization. Attackers can inject arbitrary JavaS…

▾ SunlitGFI Software · HelpDeskEPSS 0.14%via CVEORG
CVE-2026-23752Medium· 4.8
5mo ago

GFI HelpDesk < 4.99.9 Stored XSS via companyname Parameter

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated administrators to inject arbitrary JavaScript by manipulating the companyn…

▾ SunlitGFI Software · HelpDeskEPSS 0.15%via CVEORG
HelpDesk vulnerabilities (CVEs) · VulnSea