Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

freescout-help-desk — Vulnerabilities & Security Advisories 73

Browse all 73 CVE security advisories affecting freescout-help-desk. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FreeScout is an open-source, self-hosted help desk application designed to manage customer support tickets via email, serving as a cost-effective alternative to commercial platforms. Despite its utility, the software has a significant security history, with 56 Common Vulnerabilities and Exposures (CVEs) currently recorded. These vulnerabilities predominantly involve cross-site scripting (XSS), SQL injection, and remote code execution (RCE), often stemming from insufficient input validation and improper access controls. Several incidents highlight critical privilege escalation flaws that allow unauthenticated users to gain administrative access or execute arbitrary commands on the host system. The high volume of disclosed CVEs indicates persistent maintenance challenges regarding code quality and security auditing. Organizations deploying FreeScout must prioritize rigorous patch management and network segmentation to mitigate these known risks, as the application’s architecture has repeatedly demonstrated susceptibility to standard web application attacks.

Top products by freescout-help-desk: freescout
CVE ID Title CVSS Severity Published
CVE-2026-40568 FreeScout Vulnerable to XSS via Mailbox Signature Due to Incomplete HTML Sanitization — freescout CWE-79 8.5 High 2026-04-21
CVE-2026-40567 FreeScout has HTML Injection in Outgoing Emails via Unsanitized Customer Name in Signature Variables — freescout CWE-116 5.8 Medium 2026-04-21
CVE-2026-40566 FreeScout vulnerable to SSRF via IMAP/SMTP Connection Test Endpoints — freescout CWE-918 4.1 Medium 2026-04-21
CVE-2026-40565 FreeScout has Stored XSS / CSS Injection via linkify() — Unescaped URL in Anchor href — freescout CWE-79 6.1 Medium 2026-04-21
CVE-2026-40498 FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron — freescout CWE-200 9.1AI Critical AI 2026-04-21
CVE-2026-40497 FreeScout Vulnerable to CSS Injection via Stored Style Tag in Mailbox Signature (CSRF Token Exfiltration) — freescout CWE-79 8.1 High 2026-04-21
CVE-2026-40496 FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force — freescout CWE-330 8.2AI High AI 2026-04-21
CVE-2026-35584 FreeScout has an Unauthenticated IDOR in Open Tracking Endpoint Allows Cross-Conversation Thread Manipulation and Enumeration — freescout CWE-306 8.2AI High AI 2026-04-07
CVE-2026-39384 FreeScout Customer Merge Cross-Mailbox Authorization Bypass — freescout CWE-639 7.6 High 2026-04-07
CVE-2026-34442 FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout — freescout CWE-20 5.4 Medium 2026-03-31
CVE-2026-34443 FreeScout: SSRF protection bypass via broken CIDR check in checkIpByMask() — freescout CWE-918 7.5 - 2026-03-31
CVE-2026-32754 FreeScout: Stored XSS via Unescaped Email Template Rendering ({!! $thread->body !!}) — freescout CWE-79 9.3 Critical 2026-03-19
CVE-2026-32753 FreeScout: Stored XSS through SVG file upload with filter bypass — freescout CWE-80 6.1 - 2026-03-19
CVE-2026-32752 FreeScout: Broken Access Control in ThreadPolicy — Any User Can Read/Edit All Customer Messages — freescout CWE-284 - - 2026-03-19
CVE-2026-28289 FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to Remote Code Execution — freescout CWE-434 10.0 Critical 2026-03-03
CVE-2026-27636 FreeScout: Missing .htaccess in Restricted File Extensions Allows Remote Code Execution on Apache — freescout CWE-434 8.8 High 2026-02-25
CVE-2026-27637 FreeScout's Predictable Authentication Token Enables Account Takeover — freescout CWE-330 9.8 Critical 2026-02-25
CVE-2025-58163 FreeScout's deserialization of untrusted data can lead to Remote Code Execution — freescout CWE-502 7.5AI High AI 2025-09-03
CVE-2025-54366 FreeScout's deserialization of untrusted data leads to Remote Code Execution — freescout CWE-502 8.8 - 2025-07-26
CVE-2025-48488 FreeScout Vulnerable to Stored XSS — freescout CWE-79 5.4AI Medium AI 2025-05-30
CVE-2025-48880 FreeScout has Race Condition When Deleting Users — freescout CWE-362 4.2AI Medium AI 2025-05-30
CVE-2025-48875 FreeScout Vulnerable to Stored XSS — freescout CWE-79 5.4AI Medium AI 2025-05-30
CVE-2025-48489 FreeScout Vulnerable to Stored XSS — freescout CWE-79 5.4AI Medium AI 2025-05-30
CVE-2025-48487 FreeScout Vulnerable to Stored XSS — freescout CWE-79 5.4AI Medium AI 2025-05-30
CVE-2025-48486 FreeScout Vulnerable to Stored XSS — freescout CWE-79 5.4AI Medium AI 2025-05-30
CVE-2025-48485 FreeScout Vulnerable to Stored XSS — freescout CWE-79 5.4AI Medium AI 2025-05-30
CVE-2025-48484 FreeScout Vulnerable to Stored XSS — freescout CWE-79 5.4AI Medium AI 2025-05-30
CVE-2025-48483 FreeScout Stored XSS leads to CSRF — freescout CWE-79 6.1AI Medium AI 2025-05-30
CVE-2025-48482 FreeScout Has Business Logic Errors — freescout CWE-841 4.3AI Medium AI 2025-05-30
CVE-2025-48481 FreeScout Has Business Logic Errors — freescout CWE-841 8.2AI High AI 2025-05-30

This page lists every published CVE security advisory associated with freescout-help-desk. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.