Freescout
30 CVEs tracked since 2025. Since May 2025, none of them reached CISA KEV.
Freescout CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-05 | 24 | 0 |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | null or fewer | |
| 2026-04 | 6 | 0 |
Products
The products that kept showing up in Freescout's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Freescout.
- CVE-2026-40565FreeScout has Stored XSS / CSS Injection via linkify() — Unescaped URL in Anchor href6.1
- CVE-2026-40498FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron9.8
- CVE-2026-40497FreeScout Vulnerable to CSS Injection via Stored Style Tag in Mailbox Signature (CSRF Token Exfiltration)8.1
- CVE-2026-40496FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force9.1
- CVE-2026-35584FreeScout has an Unauthenticated IDOR in Open Tracking Endpoint Allows Cross-Conversation Thread Manipulation and Enumeration6.5
- CVE-2026-39384FreeScout Customer Merge Cross-Mailbox Authorization Bypass7.6
- CVE-2026-34442FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout5.4
- CVE-2026-34443FreeScout: SSRF protection bypass via broken CIDR check in checkIpByMask()5.3
- CVE-2026-32754FreeScout: Stored XSS via Unescaped Email Template Rendering ({!! $thread->body !!})9.3
- CVE-2026-32753FreeScout: Stored XSS through SVG file upload with filter bypass5.4
- CVE-2026-32752FreeScout: Broken Access Control in ThreadPolicy — Any User Can Read/Edit All Customer Messages—
- CVE-2026-28289FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to Remote Code Execution10.0
- CVE-2026-27636FreeScout: Missing .htaccess in Restricted File Extensions Allows Remote Code Execution on Apache8.8
- CVE-2026-27637FreeScout's Predictable Authentication Token Enables Account Takeover9.8
- CVE-2025-58163FreeScout's deserialization of untrusted data can lead to Remote Code Execution8.8
The record
- Peak rank
- #42 in May 2025
- Busiest month shown
- May 2025, 24 CVEs
- Months with a KEV entry
- 0 since May 2025
- Monthly snapshots
- 2 since 2025