Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

JS Help Desk — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in JS Help Desk, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumeration (CWE) vulnerability data associated with the JS Help Desk product developed by the vendor JS Help Desk. The content compiles a comprehensive list of security flaws, ranging from cross-site scripting and injection attacks to improper access control issues, covering reported incidents from the earliest tracked releases through the most recent patches. Readers can utilize this resource to effectively track a vendor's advisories by following the chronological progression of disclosed issues and fixes, gain a deeper understanding of a specific weakness class by observing its recurrence and exploitation patterns within this specific software ecosystem, and meticulously look up a product's vulnerability history to assess the overall security posture and remediation speed of JS Help Desk over time. This structured overview serves as a neutral reference point for security analysts, developers, and IT administrators who need to evaluate the risk landscape without navigating fragmented news sources or fragmented vendor communication channels. By centralizing this information, the page facilitates a clearer view of how the product has evolved in response to security challenges, allowing stakeholders to make informed decisions regarding deployment, maintenance, and risk mitigation strategies. The data presented reflects publicly available information and aims to provide transparency into the software's security track record.

Vendor: JS Help Desk

CVE IDTitleCVSSSeverityPublished
CVE-2026-15209 JS Help Desk – AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cross-User Support Ticket Disclosure via IDOR --2026-07-31
CVE-2026-14930 JS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment Upload --2026-07-31
CVE-2026-14931 JS Help Desk < 3.1.4 - Contributor+ User Email Disclosure --2026-07-31
CVE-2026-14929 JS Help Desk < 3.1.4 - Subscriber+ Ticket Reply Modification via IDOR --2026-07-31
CVE-2026-14928 JS Help Desk < 3.1.4 - Subscriber+ Sensitive Information Disclosure via checkAIReplyTicketsBySubject --2026-07-31
CVE-2026-57652 WordPress JS Help Desk plugin <= 3.1.0 - Insecure Direct Object References (IDOR) vulnerability CWE-639 5.3 Medium2026-06-26
CVE-2026-56054 WordPress JS Help Desk plugin <= 3.1.1 - Arbitrary File Deletion vulnerability CWE-22 7.7 High2026-06-25
CVE-2026-48887 WordPress JS Help Desk plugin <= 3.0.9 - Broken Access Control vulnerability CWE-862 6.5 Medium2026-06-15
CVE-2026-48886 WordPress JS Help Desk plugin <= 3.0.9 - SQL Injection vulnerability CWE-89 9.3 Critical2026-06-15
CVE-2026-32534 WordPress JS Help Desk plugin <= 3.0.3 - SQL Injection vulnerability CWE-89 8.5 High2026-03-25
CVE-2026-32535 WordPress JS Help Desk plugin <= 3.0.3 - Insecure Direct Object References (IDOR) vulnerability CWE-639 6.5 Medium2026-03-25
CVE-2026-24959 WordPress JS Help Desk plugin <= 3.0.1 - SQL Injection vulnerability CWE-89 8.5 High2026-02-20
CVE-2025-30880 WordPress JS Help Desk plugin <= 2.9.2 - Broken Access Control vulnerability CWE-862 7.5 High2025-04-01
CVE-2025-30901 WordPress JS Help Desk plugin <= 2.9.2 - Local File Inclusion vulnerability CWE-98 8.1 High2025-04-01
CVE-2025-30886 WordPress JS Help Desk plugin <= 2.9.2 - SQL Injection vulnerability CWE-89 9.3 Critical2025-04-01
CVE-2025-30882 WordPress JS Help Desk plugin <= 2.9.1 - Arbitrary File Download vulnerability CWE-22 7.5 High2025-04-01
CVE-2025-30878 WordPress JS Help Desk plugin <= 2.9.2 - Arbitrary File Deletion vulnerability CWE-22 8.6 High2025-04-01
CVE-2024-51670 WordPress JS Help Desk plugin <= 2.8.7 - Stored Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium2024-11-09
CVE-2023-23679 WordPress JS Help Desk – Best Help Desk & Support Plugin Plugin <= 2.7.7 is vulnerable to Insecure Direct Object References (IDOR) CWE-639 4.6 Medium2023-06-23
CVE-2022-46842 WordPress JS Help Desk plugin <= 2.7.1 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 5.4 Medium2023-02-02

All 20 known CVE vulnerabilities affecting JS Help Desk with full Chinese analysis, references, and POCs where available.