CVE Tools

Freescout

30 CVEs tracked since 2025. Since May 2025, none of them reached CISA KEV.

Freescout CVEs per month

May 2025 to Apr 2026. Point at a month, or focus the strip and use the arrow keys.
Freescout CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-05240
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-0460

Products

The products that kept showing up in Freescout's monthly top three, with their CVEs summed over those months.

  1. Freescout302 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Freescout.

  1. CVE-2026-40565FreeScout has Stored XSS / CSS Injection via linkify() — Unescaped URL in Anchor href6.1
  2. CVE-2026-40498FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron9.8
  3. CVE-2026-40497FreeScout Vulnerable to CSS Injection via Stored Style Tag in Mailbox Signature (CSRF Token Exfiltration)8.1
  4. CVE-2026-40496FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force9.1
  5. CVE-2026-35584FreeScout has an Unauthenticated IDOR in Open Tracking Endpoint Allows Cross-Conversation Thread Manipulation and Enumeration6.5
  6. CVE-2026-39384FreeScout Customer Merge Cross-Mailbox Authorization Bypass7.6
  7. CVE-2026-34442FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout5.4
  8. CVE-2026-34443FreeScout: SSRF protection bypass via broken CIDR check in checkIpByMask()5.3
  9. CVE-2026-32754FreeScout: Stored XSS via Unescaped Email Template Rendering ({!! $thread->body !!})9.3
  10. CVE-2026-32753FreeScout: Stored XSS through SVG file upload with filter bypass5.4
  11. CVE-2026-32752FreeScout: Broken Access Control in ThreadPolicy — Any User Can Read/Edit All Customer Messages—
  12. CVE-2026-28289FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to Remote Code Execution10.0
  13. CVE-2026-27636FreeScout: Missing .htaccess in Restricted File Extensions Allows Remote Code Execution on Apache8.8
  14. CVE-2026-27637FreeScout's Predictable Authentication Token Enables Account Takeover9.8
  15. CVE-2025-58163FreeScout's deserialization of untrusted data can lead to Remote Code Execution8.8

The record

Peak rank
#42 in May 2025
Busiest month shown
May 2025, 24 CVEs
Months with a KEV entry
0 since May 2025
Monthly snapshots
2 since 2025
Freescout's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store