Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▲ 32 respecto a la semana anterior
Críticas / altas1474▲ 364 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
–

144 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2)0.51%—Faveo HelpdeskAI24/8/202627/8/2026
A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be launched remotely. The exploit has been…
AplazadaMedia (5.5)0.72%—Faveo HelpdeskAI24/8/202626/8/2026
A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The…
AplazadaMedia (5.3)0.29%—Django-helpdeskAI13/8/20269/9/2026
django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by submitting HTML-formatted email messages or uploading .html/.htm file attachments through public ticket submission channels. Attackers can exploit the lack of…
AplazadaMedia (6.5)0.37%—Ladybirdweb Faveo HelpdeskAI11/8/20263/9/2026
A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via the v1 REST API. The API verifies the existence of the requested ticket but not ownership, enabling any authenticated user to access…
AplazadaMedia (6.5)0.34%—Jshelpdesk JS Help DeskAI31/7/202626/8/2026
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.
AplazadaMedia (6.5)0.37%—Jshelpdesk JS Help DeskAI31/7/202626/8/2026
The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users.
AplazadaAlta (7.5)0.41%—Jshelpdesk JS Help DeskAI31/7/202626/8/2026
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users'…
AplazadaMedia (4.3)0.25%—Jshelpdesk JS Help DeskAI31/7/202626/8/2026
The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site.
AplazadaMedia (6.5)0.37%—Jshelpdesk JS Help DeskAI31/7/202626/8/2026
The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets.
AplazadaCrítica (9.8)0.95%—Customer Support Ticket System HelpdeskAI23/7/202623/7/2026
The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. This makes it possible for unauthenticated…
AplazadaMedia (5.3)0.31%—Jshelpdesk JS Help DeskAI26/6/202626/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.
AplazadaAlta (7.7)0.47%—Jshelpdesk JS Help DeskAI25/6/202625/6/2026
Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
AplazadaAlta (7.4)0.28%—Chatway Live Chat - AI Chatbot Customer Support FAQ & Helpdesk Customer Service & Chat ButtonsAI15/6/202617/6/2026
Subscriber Sensitive Data Exposure in Chatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &amp; Helpdesk Customer Service &amp; Chat Buttons <= 1.4.8 versions.
AplazadaAlta (8.5)0.36%—Elex Wordpress Helpdesk & Customer Ticketing SystemAI15/6/202617/6/2026
Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.
AplazadaMedia (6.5)0.33%—Jshelpdesk JS Help DeskAI15/6/202617/6/2026
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.
AplazadaCrítica (9.3)0.40%—Jshelpdesk JS Help DeskAI15/6/202617/6/2026
Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.
AnalizadaMedia (6.4)0.15%—GFI Helpdesk20/4/202617/6/2026
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the editsubject POST parameter. Attackers can inject XSS payloads through inadequate sanitization in…
AnalizadaMedia (5.1)0.14%—GFI Helpdesk20/4/202617/6/2026
GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly to SWIFT_Report::Create() without HTML sanitization. Attackers can inject arbitrary JavaScript into the report title field when creating or editing a report, and the…
AnalizadaMedia (5.1)0.14%—GFI Helpdesk20/4/202617/6/2026
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Controller_Step.InsertSubmit() and EditSubmit() before being rendered by View_Step.RenderViewSteps(). An authenticated staff member can inject arbitrary…
AnalizadaMedia (4.8)0.15%—GFI Helpdesk20/4/202617/6/2026
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality where the charset POST parameter is passed directly to SWIFT_Language::Create() without HTML sanitization and subsequently rendered unsanitized by View_Language.RenderGrid(). An authenticated…
AnalizadaMedia (4.8)0.15%—GFI Helpdesk20/4/202617/6/2026
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated administrators to inject arbitrary JavaScript by manipulating the companyname POST parameter without HTML sanitization. Attackers can inject malicious…
Pendiente de análisisMedia (4.3)0.17%—Vision HelpdeskAI16/4/202617/6/2026
Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie data to vis_client_id.
AplazadaAlta (7.5)0.30%—Jshelpdesk JS Help DeskAI26/3/202617/6/2026
The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, and including, 3.0.4. This is due to the user-supplied `multiformid` value being passed to `esc_sql()` without enclosing…
AplazadaAlta (7.5)0.37%—Wpfactory Helpdesk Support Ticket System FOR WoocommerceAI25/3/202617/6/2026
Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.2.
AplazadaAlta (7.5)1.3%—Jshelpdesk JS Help DeskAI4/3/202617/6/2026
The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in version 2.8.2 due to an incomplete fix for CVE-2023-50839 where a second sink was left with insufficient escaping on the user supplied values and lack of…