VulnSea

uvdesk has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 6.3 (medium), with 1 rated critical. Most affected products: core-framework (3), community-skeleton (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.3
Publish → KEV
Last 90 days
4 prev 0

Products

  • core-framework 3
  • community-skeleton 1
4
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

uvdesk vulnerabilities

CVEs affecting uvdesk, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2025-71421High· 7.2
today

UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator

UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit the…

Twilightuvdesk · core-frameworkvia NVD
CVE-2025-71420Medium· 4.3PoC
today

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate …

Twilightuvdesk · core-frameworkvia NVD
CVE-2025-71419Medium· 5.4
today

UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action

UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script …

Sunlituvdesk · core-frameworkvia NVD
CVE-2026-92805Critical· 9.8PoC
5d ago

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator a…

Abyssaluvdesk · community-skeletonEPSS 0.35%via NVD
uvdesk vulnerabilities (CVEs) · VulnSea