Freescout-help-desk
63 CVEs tracked since 2025. Since May 2025, none of them reached CISA KEV.
Freescout-help-desk CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-05 | 24 | 0 |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | null or fewer | |
| 2026-04 | 22 | 0 |
| 2026-05 | 9 | 0 |
| 2026-06 | null or fewer | |
| 2026-07 | 8 | 0 |
Products
The products that kept showing up in Freescout-help-desk's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Freescout-help-desk.
- CVE-2026-53596FreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)5.3
- CVE-2026-53595FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL9.4
- CVE-2026-53594FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path4.9
- CVE-2026-53593FreeScout Vulnerable to Authenticated Remote Code Execution via incomplete upload extension denylist (.pht) — bypass of CVE-2025-484718.8
- CVE-2026-53592FreeScout vulnerable to prototype pollution in getQueryParam4.6
- CVE-2026-53591FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmails8.6
- CVE-2026-48812FreeScout Allows Unauthenticated Access to Legacy Attachment Files7.5
- CVE-2026-45295FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation Enumeration via Open Tracking Endpoint6.5
- CVE-2026-45294FreeScout: User Account Enumeration via Password Reset Response Differentiation5.3
- CVE-2026-47123FreeScout: Agent Impersonation via Missing HMAC Verification on Notification Reply Message-ID Path7.5
- CVE-2026-48810FreeScout: Thread Edit Authorization Bypass via Missing Mailbox Check4.3
- CVE-2026-48811FreeScout: Thread Deletion Bypasses Mailbox Access Revocation4.3
- CVE-2026-41906FreeScout: Conversation Change-Customer Cross-Mailbox Authorization Bypass7.1
- CVE-2026-41905FreeScout vulnerable to SSRF via Helper::sanitizeRemoteUrl: redirect destination not re-validated, allowing internal HTTP / cloud-metadata access7.7
- CVE-2026-41904FreeScout Stored XSS vulnerability in mailbox auto-reply: payload reaches every customer's email client (no CSP), bypassing strip_tags validator with mixed text+HTML content7.6
The record
- Peak rank
- #41 in Apr 2026
- Busiest month shown
- May 2025, 24 CVEs
- Months with a KEV entry
- 0 since May 2025
- Monthly snapshots
- 4 since 2025