« Volver al listado

Jshelpdesk

Jshelpdesk JS Help Desk: vulnerabilidades y CVE

Jshelpdesk JS Help Desk tiene 12 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses11
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-15209Media (6.5)0.34%—31 jul 2026
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's…
CVE-2026-14931Media (6.5)0.37%—31 jul 2026
The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users…
CVE-2026-14930Alta (7.5)0.41%—31 jul 2026
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk…
CVE-2026-14929Media (4.3)0.25%—31 jul 2026
The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket…
CVE-2026-14928Media (6.5)0.37%—31 jul 2026
The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and…
CVE-2026-57652Media (5.3)0.31%—26 jun 2026
Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.
CVE-2026-56054Alta (7.7)0.47%—25 jun 2026
Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
CVE-2026-48887Media (6.5)0.33%—15 jun 2026
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.
CVE-2026-48886Crítica (9.3)0.40%—15 jun 2026
Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.
CVE-2026-2511Alta (7.5)0.30%—26 mar 2026
The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, and including, 3.0.4.…
CVE-2023-7337Alta (7.5)1.3%—4 mar 2026
The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in version 2.8.2 due to an incomplete fix for CVE-2023-50839…
CVE-2024-7094Crítica (9.8)38%—13 ago 2024
The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme'…

Otros productos de Jshelpdesk