Joomsky
Joomsky JS Help Desk: vulnerabilidades y CVE
Joomsky JS Help Desk tiene 15 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses3
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-32535 | Media (6.5) | 0.27% | — | 25 mar 2026 | Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a… |
| CVE-2026-32534 | Alta (8.5) | 0.36% | — | 25 mar 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk: from n/a through… |
| CVE-2026-24959 | Alta (8.5) | 0.22% | — | 20 feb 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk: from n/a through… |
| CVE-2025-30901 | Alta (8.1) | 0.85% | — | 1 abr 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Help Desk js-support-ticket allows PHP Local File Inclusion.This issue affects JS Help… |
| CVE-2025-30886 | Crítica (10) | 0.52% | — | 1 abr 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows SQL Injection.This issue affects JS Help Desk: from n/a through <=… |
| CVE-2025-30882 | Alta (7.5) | 0.59% | — | 1 abr 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-support-ticket allows Path Traversal.This issue affects JS Help Desk: from n/a through <= 2.9.1. |
| CVE-2025-30880 | Alta (7.5) | 0.49% | — | 1 abr 2025 | Missing Authorization vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through <= 2.9.2. |
| CVE-2025-30878 | Crítica (9.1) | 0.62% | — | 1 abr 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-support-ticket allows Path Traversal.This issue affects JS Help Desk: from n/a through <= 2.9.2. |
| CVE-2022-46840 | Media (5.4) | 0.45% | — | 13 dic 2024 | Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk… |
| CVE-2022-46838 | Crítica (9.1) | 0.73% | — | 13 dic 2024 | Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk… |
| CVE-2024-51670 | Media (4.8) | 0.26% | — | 9 nov 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JoomSky JS Help Desk js-support-ticket allows Stored XSS.This issue affects JS Help Desk: from n/a through <= 2.8.7. |
| CVE-2024-43274 | Crítica (9.8) | 0.44% | — | 1 nov 2024 | Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JS Help Desk – Best Help Desk &… |
| CVE-2023-25444 | Crítica (9.1) | 0.84% | — | 17 may 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Using Malicious Files.This issue affects JS Help Desk – Best Help Desk & Support… |
| CVE-2022-47151 | Alta (8.6) | 0.44% | — | 17 abr 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk &… |
| CVE-2018-21002 | Alta (8.8) | 0.68% | — | 27 ago 2019 | The js-support-ticket plugin before 2.0.6 for WordPress has CSRF. |