VulnSea

helpdesk vulnerabilities

CVEs whose affected-version data names the helpdesk package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-23756Medium· 5.4
5mo ago

GFI HelpDesk < 4.99.9 Stored XSS via Troubleshooter Step Subject

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Controller_Step.InsertSubmit() and EditSubmit() before being rendered by Vi…

▾ SunlitGFI Software · HelpDeskEPSS 0.14%via CVEORG
CVE-2026-23753Medium· 4.8
5mo ago

GFI HelpDesk < 4.99.9 Stored XSS via charset Parameter

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality where the charset POST parameter is passed directly to SWIFT_Language::Create() without HTML sanitization and subseq…

▾ SunlitGFI Software · HelpDeskEPSS 0.15%via CVEORG
CVE-2026-23758Medium· 5.1
5mo ago

GFI HelpDesk < 4.99.9 Stored XSS via editsubject Parameter

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the editsubject POST parameter. Attackers …

▾ SunlitGFI Software · HelpDeskEPSS 0.15%via CVEORG
CVE-2026-23757Medium· 5.4
5mo ago

GFI HelpDesk < 4.99.10 Stored XSS via Reports Module

GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly to SWIFT_Report::Create() without HTML sanitization. Attackers can inject arbitrary JavaS…

▾ SunlitGFI Software · HelpDeskEPSS 0.14%via CVEORG
CVE-2026-23752Medium· 4.8
5mo ago

GFI HelpDesk < 4.99.9 Stored XSS via companyname Parameter

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated administrators to inject arbitrary JavaScript by manipulating the companyn…

▾ SunlitGFI Software · HelpDeskEPSS 0.15%via CVEORG
CVE-2025-10655High· 8.8
10mo ago

SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0.

SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0.

▾ Twilightfrappe · helpdeskEPSS 0.56%via NVD
helpdesk vulnerabilities (CVEs) · VulnSea