Freshworks operates a focused portfolio of cloud-based customer-engagement and IT-service-management products, including FreshService and FreshDesk, that handle sensitive business communication and support workflows. The durable vulnerability signal centers on trust-boundary and validation issues: certificate validation failures, integrity-check bypasses, and open-redirect conditions that reflect the authentication and session-handling demands of cloud SaaS platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freshworks over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36174HIGH FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulnerable to Broken integrity checking via the FreshAgent client | Sep 12, 2022 | 8.1 | 26 | NO | NO |
CVE-2022-36173HIGH FreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the FreshAgent client and scheduled update service. | Sep 12, 2022 | 8.1 | 26 | NO | NO |
CVE-2015-10102MEDIUM A vulnerability, which was classified as critical, has been found in Freshdesk Plugin 1.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads | Apr 17, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freshworks.
Media articles that mention a CVE ID that affects a product developed by Freshworks — matched by CVE ID, not by vendor name.