Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Deskpro

First CVE: Nov 17, 2003Active for: 23 yearsTotal CVEs: 13
30.9
VTI Score
Low

Deskpro is a focused help-desk and customer-support ticketing platform whose vulnerability profile concentrates in a single product across a narrow portfolio. The recurrent exposure centers on web-application and authorization weaknesses—including cross-site scripting, improper privilege management, missing authorization controls, and deserialization of untrusted data—that reflect the platform's role as an internal and customer-facing application handling sensitive support interactions. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Deskpro over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2003
22 years ago
Most Recent CVE
Jul 21, 2023
1,100 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-2011MEDIUM
Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
Apr 12, 20074.332NOYES
CVE-2021-35391HIGH
Server Side Request Forgery vulnerability found in Deskpro Support Desk v2021.21.6 allows attackers to execute arbitrary code via a crafted URL.
Jul 21, 20237.225NONO
CVE-2020-11465HIGH
An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk appli
Apr 1, 20208.822NONO
CVE-2020-11467HIGH
An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface by editing /portal/api/style/edit-theme-set/template-source
Apr 1, 20207.220NONO
CVE-2020-11463HIGH
An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve cleartext cred
Apr 1, 20207.520NONO
CVE-2021-36695MEDIUM
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile du
Sep 8, 20215.419NONO
CVE-2021-36696MEDIUM
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social media links on a user profile due to lack
Sep 7, 20215.419NONO
CVE-2020-28722MEDIUM
Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templ
May 12, 20215.418NONO
CVE-2006-6159MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in DeskPRO 2.0.0 and 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) message or
Nov 28, 20066.818NONO
CVE-2020-11464MEDIUM
An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve sensitive information
Apr 1, 20204.317NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
69%
31%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network9 (69.2%)
Unknown4 (30.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (69.2%)
High0 (0.0%)
Unknown4 (30.8%)
User Interaction
None6 (46.2%)
Unknown4 (30.8%)
Required3 (23.1%)
Privileges Required
Low6 (46.2%)
High2 (15.4%)
None1 (7.7%)
Unknown4 (30.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Deskpro.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Deskpro — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Deskpro's Products

View all 1 CNAs →

Top CWEs