Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-23757

21
FAUCET Score

GFI HelpDesk versions prior to 4.99.10 contain a stored cross-site scripting (XSS) vulnerability in the Reports module where user-supplied input in the report title parameter is not properly sanitized before being processed by the SWIFT_Report::Create() function. An authenticated attacker can inject malicious JavaScript code into report titles, and this payload will execute in the browsers of staff members when they view or interact with the affected report in the Manage Reports interface. The vulnerability has a CVSS score of 5.4 (Medium) and requires network access with low complexity, but necessitates user interaction and valid credentials to exploit. The attack vector is network-based, and successful exploitation could result in limited confidentiality and integrity impacts through session hijacking, credential theft, or administrative actions performed in the context of the victim's browser. There is currently no evidence of active exploitation in the wild, no public exploit code availability, and minimal community attention as reflected by the low EPSS score of 0.00029. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hotlists. Organizations running affected versions should apply patches at their standard maintenance cadence, prioritizing systems with high user interaction in the Reports module.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.99.10CPE matchmatch criteria
cpe:2.3:a:gfi:helpdesk:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.1MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
3.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 1st percentile among its peer group of 15,225 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

gfi.ai / products-and-solutions/email-and-messaging-solutions/helpdesk/resources/product-releases
Release Notes
vulncheck.com / advisories/gfi-helpdesk-stored-xss-via-reports-module
Third Party Advisory