Freescout is an open-source help-desk and customer-support platform that, despite its narrow product focus, occupies a prominent position in the self-hosted ticketing software landscape. Vulnerabilities affecting the platform skew toward serious outcomes, with a meaningful share reaching critical severity, and recur consistently around input-handling and access-control weaknesses including cross-site scripting, improper workflow enforcement, incorrect authorization, and unrestricted file uploads—exposures characteristic of web applications that process user input and manage role-based permissions. The platform's self-hosted deployment model means affected instances require direct patching by operators rather than vendor-pushed updates, making timely awareness of these disclosures particularly important for defenders running Freescout in production. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freescout over time
Signals from CVEs in this vendor scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-28289HIGH FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authe | Mar 3, 2026 | 8.1 | 62 | NO | YES |
CVE-2026-27636HIGH FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file upload restriction list in `app/Misc/Helper.php` does | Feb 25, 2026 | 8.8 | 46 | NO | YES |
CVE-2026-40498CRITICAL FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system tools that should be restricted | Apr 21, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-32754CRITICAL FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout' | Mar 19, 2026 | 9.3 | 30 | NO | NO |
CVE-2025-48471CRITICAL FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, the application does not check or performs insufficient checking of files uploaded to the ap | May 29, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-40496CRITICAL FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY | Apr 21, 2026 | 9.1 | 29 | NO | NO |
CVE-2026-27637CRITICAL FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses a predictable authentication to | Feb 25, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-54366HIGH FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1.8.185 and below, there is a critical deserialization vulner | Jul 26, 2025 | 8.8 | 29 | NO | NO |
CVE-2026-40497HIGH FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDangerousTags()` removes `<script>`, `<form>`, `<iframe>`, `<objec | Apr 21, 2026 | 8.1 | 28 | NO | NO |
CVE-2025-58163HIGH FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.185 and earlier contain a deserialization of untrusted data vulnerability that allow | Sep 3, 2025 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (46 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freescout.
Media articles that mention a CVE ID that affects a product developed by Freescout — matched by CVE ID, not by vendor name.