Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 1.3% | 💥 Exploit | Jshelpdesk JS Help DeskAI | 4/3/2026 | 17/6/2026 | The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in version 2.8.2 due to an incomplete fix for CVE-2023-50839 where a second sink was left with insufficient escaping on the user supplied values and lack of… | |
| Aplazada | Media (6.5) | 0.26% | — | Elextensions Elex Wordpress Helpdesk Customer Support Ticket SystemAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ELEX WordPress HelpDesk & Customer Ticketing System: from n/a through <= 3.3.5. | |
| Aplazada | Alta (8.2) | 0.28% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.8. | |
| Aplazada | Media (5.3) | 0.30% | — | Elex Wordpress Helpdesk Customer Ticketing SystemAI | 5/2/2026 | 17/6/2026 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.5. This is due to missing capability checks on the eh_crm_ticket_general function combined with a shared nonce that is exposed to low-privileged users. This… | |
| Aplazada | Media (5.1) | 0.17% | — | Maian Support HelpdeskAI | 3/2/2026 | 17/6/2026 | Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authentication. Attackers can craft malicious HTML forms to add admin users and upload PHP files with unrestricted file upload capabilities through the FAQ attachment system. | |
| Aplazada | Media (4.3) | 0.16% | — | Helpdesk Contact FormAI | 7/1/2026 | 17/6/2026 | The HelpDesk contact form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing or incorrect nonce validation on the handle_query_args() function. This makes it possible for unauthenticated attackers to update the plugin's license ID and… | |
| Aplazada | Media (5.3) | 0.22% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 23/12/2025 | 17/6/2026 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.9. | |
| Aplazada | Alta (7.2) | 0.23% | — | Elex Wordpress Helpdesk Customer Ticketing SystemAI | 21/12/2025 | 28/9/2026 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket subjects in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Analizada | Alta (8.6) | 0.56% | — | Frappe Helpdesk | 9/12/2025 | 17/6/2026 | SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0. | |
| Aplazada | Crítica (10) | 0.45% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 6/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Remote Code Inclusion.This issue affects HAPPY: from n/a through <= 1.0.7. | |
| Aplazada | Media (4.3) | 0.25% | — | Wpfactory Helpdesk Support Ticket System FOR WoocommerceAI | 22/9/2025 | 1/10/2026 | Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.1. | |
| Aplazada | Media (6.5) | 0.23% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 5/9/2025 | 17/6/2026 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.6. | |
| Aplazada | Alta (8.1) | 0.71% | — | Wordpress Helpdesk IntegrationAI | 5/9/2025 | 25/9/2026 | The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.8.10 via the portal_type parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP… | |
| Analizada | Media (4.4) | 0.21% | — | Django-helpdesk Project Django-helpdesk | 31/5/2025 | 17/6/2026 | django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py. | |
| Aplazada | Media (6.5) | 0.27% | — | Vision HelpdeskAI | 15/4/2025 | 17/6/2026 | Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed. | |
| Aplazada | Alta (7.1) | 0.29% | — | M. ALI Saleem Support Helpdesk Ticket System LiteAI | 3/4/2025 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alisaleem252 Support Helpdesk Ticket System Lite ticket-help-desk-system-lite allows Reflected XSS.This issue affects Support Helpdesk Ticket System Lite: from n/a through 4.5.2. | |
| Analizada | Alta (7.7) | 0.31% | — | Qnap Helpdesk | 7/3/2025 | 17/6/2026 | An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: Helpdesk 3.3.3 and later | |
| Analizada | Media (4.8) | 0.27% | — | Helpdeskz | 26/2/2025 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ticket. | |
| Aplazada | Media (4.3) | 0.42% | — | Jshelpdesk THE Ultimate Help Desk AND Support PluginAI | 4/2/2025 | 17/6/2026 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.8 via the 'exportusereraserequest' due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.17% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function. | |
| Analizada | Media (6.1) | 0.23% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function. | |
| Analizada | Alta (7.5) | 0.97% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function. | |
| Analizada | Alta (8.1) | 0.33% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can delete admin users by sending a request to the "WSCView/Delete" function. | |
| Analizada | Media (6.1) | 0.28% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function. | |
| Analizada | Media (6.5) | 0.70% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticated SOAP requests to the WSConnector service. |