Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-23753

19
FAUCET Score

GFI HelpDesk versions prior to 4.99.9 contain a stored cross-site scripting vulnerability in the language management feature where the charset parameter fails to properly sanitize user input before storing and displaying it. An authenticated administrator can inject malicious JavaScript through the charset field when creating or editing languages, with the payload executing in the browsers of other administrators accessing the Languages page. The vulnerability affects network-accessible GFI HelpDesk installations and requires administrator-level privileges to exploit. The vulnerability carries a CVSS score of 4.8 (Medium severity) with a network attack vector and low attack complexity. While the impact is limited to low-level confidentiality and integrity compromises with no availability impact, the requirement for high-level administrative privileges reduces overall risk. Exploitation requires user interaction, as the malicious payload only executes when other administrators view the Languages page. There is currently no evidence of active exploitation, with the vulnerability absent from CISA's Known Exploited Vulnerabilities catalog. The EPSS score of 0.00027 indicates minimal likelihood of exploitation in the wild relative to other CVEs. The vulnerability remains on an inactive hot list status with no publicly available exploit code or significant community attention, suggesting limited current threat activity.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.99.9CPE matchmatch criteria
cpe:2.3:a:gfi:helpdesk:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

4.8MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
HIGH
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 1st percentile among its peer group of 4,937 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

gfi.ai / products-and-solutions/email-and-messaging-solutions/helpdesk/resources/product-releases
Release Notes
vulncheck.com / advisories/gfi-helpdesk-stored-xss-via-charset-parameter
Third Party Advisory