Simple-help
Simple-help Simplehelp: vulnerabilities and CVEs
Simple-help Simplehelp has 6 published vulnerabilities, 1 of them in the last 12 months. 2 are rated critical and 4 are listed by CISA as actively exploited.
CVEs6
Last 12 months1
Critical2
Actively exploited4
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48558 | Critical (9.5) | 5.7% | ⚠ Active exploitation | Jun 12, 2026 | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during… |
| CVE-2024-57726 | Critical (9.9) | 67% | ⚠ Active exploitation | Jan 15, 2025 | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the… |
| CVE-2024-57728 | High (7.2) | 65% | ⚠ Active exploitation | Jan 15, 2025 | SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary… |
| CVE-2024-57727 | High (7.5) | 97% | ⚠ Active exploitation | Jan 15, 2025 | SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48558 | Critical (9.5) | 5.7% | ⚠ Active exploitation | Jun 12, 2026 | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during… |
| CVE-2025-36728 | High (8.8) | 0.17% | — | Jul 25, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11. |
| CVE-2025-36727 | High (8.8) | 0.42% | — | Jul 25, 2025 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12. |
| CVE-2024-57728 | High (7.2) | 65% | ⚠ Active exploitation | Jan 15, 2025 | SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary… |
| CVE-2024-57727 | High (7.5) | 97% | ⚠ Active exploitation | Jan 15, 2025 | SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted… |
| CVE-2024-57726 | Critical (9.9) | 67% | ⚠ Active exploitation | Jan 15, 2025 | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.