Deskpro is a focused help-desk and customer-support ticketing platform whose vulnerability profile concentrates in a single product across a narrow portfolio. The recurrent exposure centers on web-application and authorization weaknesses—including cross-site scripting, improper privilege management, missing authorization controls, and deserialization of untrusted data—that reflect the platform's role as an internal and customer-facing application handling sensitive support interactions. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Deskpro over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2011MEDIUM Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | Apr 12, 2007 | 4.3 | 32 | NO | YES |
CVE-2021-35391HIGH Server Side Request Forgery vulnerability found in Deskpro Support Desk v2021.21.6 allows attackers to execute arbitrary code via a crafted URL. | Jul 21, 2023 | 7.2 | 25 | NO | NO |
CVE-2020-11465HIGH An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk appli | Apr 1, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-11467HIGH An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface by editing /portal/api/style/edit-theme-set/template-source | Apr 1, 2020 | 7.2 | 20 | NO | NO |
CVE-2020-11463HIGH An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve cleartext cred | Apr 1, 2020 | 7.5 | 20 | NO | NO |
CVE-2021-36695MEDIUM Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile du | Sep 8, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-36696MEDIUM Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social media links on a user profile due to lack | Sep 7, 2021 | 5.4 | 19 | NO | NO |
CVE-2020-28722MEDIUM Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templ | May 12, 2021 | 5.4 | 18 | NO | NO |
CVE-2006-6159MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in DeskPRO 2.0.0 and 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) message or | Nov 28, 2006 | 6.8 | 18 | NO | NO |
CVE-2020-11464MEDIUM An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve sensitive information | Apr 1, 2020 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Deskpro.
Media articles that mention a CVE ID that affects a product developed by Deskpro — matched by CVE ID, not by vendor name.