Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Freescout

First CVE: Feb 28, 2024Active for: 2 yearsTotal CVEs: 46
46.7
VTI Score
High

Freescout is an open-source help-desk and customer-support platform that, despite its narrow product focus, occupies a prominent position in the self-hosted ticketing software landscape. Vulnerabilities affecting the platform skew toward serious outcomes, with a meaningful share reaching critical severity, and recur consistently around input-handling and access-control weaknesses including cross-site scripting, improper workflow enforcement, incorrect authorization, and unrestricted file uploads—exposures characteristic of web applications that process user input and manage role-based permissions. The platform's self-hosted deployment model means affected instances require direct patching by operators rather than vendor-pushed updates, making timely awareness of these disclosures particularly important for defenders running Freescout in production. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
46
Total CVEs
More Total CVEs than 98% of tracked vendors
15.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Freescout over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 28, 2024
2 years ago
Most Recent CVE
Apr 21, 2026
94 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-28289HIGH
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authe
Mar 3, 20268.162NOYES
CVE-2026-27636HIGH
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file upload restriction list in `app/Misc/Helper.php` does
Feb 25, 20268.846NOYES
CVE-2026-40498CRITICAL
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system tools that should be restricted
Apr 21, 20269.830NONO
CVE-2026-32754CRITICAL
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout'
Mar 19, 20269.330NONO
CVE-2025-48471CRITICAL
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, the application does not check or performs insufficient checking of files uploaded to the ap
May 29, 20259.830NONO
CVE-2026-40496CRITICAL
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY
Apr 21, 20269.129NONO
CVE-2026-27637CRITICAL
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses a predictable authentication to
Feb 25, 20269.829NONO
CVE-2025-54366HIGH
FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1.8.185 and below, there is a critical deserialization vulner
Jul 26, 20258.829NONO
CVE-2026-40497HIGH
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDangerousTags()` removes `<script>`, `<form>`, `<iframe>`, `<objec
Apr 21, 20268.128NONO
CVE-2025-58163HIGH
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.185 and earlier contain a deserialization of untrusted data vulnerability that allow
Sep 3, 20258.827NONO
View all 46 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products46 CVEs
46%
35%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network46 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (93.5%)
High3 (6.5%)
Unknown0 (0.0%)
User Interaction
None30 (65.2%)
Unknown0 (0.0%)
Required16 (34.8%)
Privileges Required
Low23 (50.0%)
High11 (23.9%)
None12 (26.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (46 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
4.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Freescout.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Freescout — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Freescout's Products

View all 2 CNAs →

Top CWEs