CVE Tools

Freescout-help-desk

63 CVEs tracked since 2025. Since May 2025, none of them reached CISA KEV.

Freescout-help-desk CVEs per month

May 2025 to Jul 2026. Point at a month, or focus the strip and use the arrow keys.
Freescout-help-desk CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-05240
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04220
2026-0590
2026-06null or fewer
2026-0780

Products

The products that kept showing up in Freescout-help-desk's monthly top three, with their CVEs summed over those months.

  1. Freescout634 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Freescout-help-desk.

  1. CVE-2026-53596FreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)5.3
  2. CVE-2026-53595FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL9.4
  3. CVE-2026-53594FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path4.9
  4. CVE-2026-53593FreeScout Vulnerable to Authenticated Remote Code Execution via incomplete upload extension denylist (.pht) — bypass of CVE-2025-484718.8
  5. CVE-2026-53592FreeScout vulnerable to prototype pollution in getQueryParam4.6
  6. CVE-2026-53591FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmails8.6
  7. CVE-2026-48812FreeScout Allows Unauthenticated Access to Legacy Attachment Files7.5
  8. CVE-2026-45295FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation Enumeration via Open Tracking Endpoint6.5
  9. CVE-2026-45294FreeScout: User Account Enumeration via Password Reset Response Differentiation5.3
  10. CVE-2026-47123FreeScout: Agent Impersonation via Missing HMAC Verification on Notification Reply Message-ID Path7.5
  11. CVE-2026-48810FreeScout: Thread Edit Authorization Bypass via Missing Mailbox Check4.3
  12. CVE-2026-48811FreeScout: Thread Deletion Bypasses Mailbox Access Revocation4.3
  13. CVE-2026-41906FreeScout: Conversation Change-Customer Cross-Mailbox Authorization Bypass7.1
  14. CVE-2026-41905FreeScout vulnerable to SSRF via Helper::sanitizeRemoteUrl: redirect destination not re-validated, allowing internal HTTP / cloud-metadata access7.7
  15. CVE-2026-41904FreeScout Stored XSS vulnerability in mailbox auto-reply: payload reaches every customer's email client (no CSP), bypassing strip_tags validator with mixed text+HTML content7.6

The record

Peak rank
#41 in Apr 2026
Busiest month shown
May 2025, 24 CVEs
Months with a KEV entry
0 since May 2025
Monthly snapshots
4 since 2025
Freescout-help-desk's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store