Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

JS Help Desk — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in JS Help Desk, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the product JS Help Desk, focusing on specific weakness types such as cross-site scripting and injection flaws. It collects historical security advisories and bug reports covering the product’s entire release lifecycle, spanning from initial public launch through recent maintenance releases. Readers can use this hub to track the vendor’s advisory history, analyze recurring weakness classes within the application, and review the complete vulnerability timeline associated with this specific help desk software. The dataset includes confirmed exploits, mitigation strategies, and patch references without listing individual CVE identifiers in the summary view. This resource supports security teams in auditing third-party software dependencies and understanding the risk profile of JS Help Desk deployments.

Vendor: JS Help Desk

CVE ID Title CVSS Severity Published
CVE-2026-15209 JS Help Desk – AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cross-User Support Ticket Disclosure via IDOR - - 2026-07-31
CVE-2026-14930 JS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment Upload - - 2026-07-31
CVE-2026-14931 JS Help Desk < 3.1.4 - Contributor+ User Email Disclosure - - 2026-07-31
CVE-2026-14929 JS Help Desk < 3.1.4 - Subscriber+ Ticket Reply Modification via IDOR - - 2026-07-31
CVE-2026-14928 JS Help Desk < 3.1.4 - Subscriber+ Sensitive Information Disclosure via checkAIReplyTicketsBySubject - - 2026-07-31
CVE-2026-57652 WordPress JS Help Desk plugin <= 3.1.0 - Insecure Direct Object References (IDOR) vulnerability CWE-639 5.3 Medium 2026-06-26
CVE-2026-56054 WordPress JS Help Desk plugin <= 3.1.1 - Arbitrary File Deletion vulnerability CWE-22 7.7 High 2026-06-25
CVE-2026-48887 WordPress JS Help Desk plugin <= 3.0.9 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-06-15
CVE-2026-48886 WordPress JS Help Desk plugin <= 3.0.9 - SQL Injection vulnerability CWE-89 9.3 Critical 2026-06-15
CVE-2026-32534 WordPress JS Help Desk plugin <= 3.0.3 - SQL Injection vulnerability CWE-89 8.5 High 2026-03-25
CVE-2026-32535 WordPress JS Help Desk plugin <= 3.0.3 - Insecure Direct Object References (IDOR) vulnerability CWE-639 6.5 Medium 2026-03-25
CVE-2026-24959 WordPress JS Help Desk plugin <= 3.0.1 - SQL Injection vulnerability CWE-89 8.5 High 2026-02-20
CVE-2025-30880 WordPress JS Help Desk plugin <= 2.9.2 - Broken Access Control vulnerability CWE-862 7.5 High 2025-04-01
CVE-2025-30901 WordPress JS Help Desk plugin <= 2.9.2 - Local File Inclusion vulnerability CWE-98 8.1 High 2025-04-01
CVE-2025-30886 WordPress JS Help Desk plugin <= 2.9.2 - SQL Injection vulnerability CWE-89 9.3 Critical 2025-04-01
CVE-2025-30882 WordPress JS Help Desk plugin <= 2.9.1 - Arbitrary File Download vulnerability CWE-22 7.5 High 2025-04-01
CVE-2025-30878 WordPress JS Help Desk plugin <= 2.9.2 - Arbitrary File Deletion vulnerability CWE-22 8.6 High 2025-04-01
CVE-2024-51670 WordPress JS Help Desk plugin <= 2.8.7 - Stored Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2024-11-09
CVE-2023-23679 WordPress JS Help Desk – Best Help Desk & Support Plugin Plugin <= 2.7.7 is vulnerable to Insecure Direct Object References (IDOR) CWE-639 4.6 Medium 2023-06-23
CVE-2022-46842 WordPress JS Help Desk plugin <= 2.7.1 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 5.4 Medium 2023-02-02

All 20 known CVE vulnerabilities affecting JS Help Desk with full Chinese analysis, references, and POCs where available.