Gestsup is a help-desk and ticketing platform whose vulnerability profile, despite limited product scope, sits within a prominent tier of tracked entities and skews toward serious outcomes. The vendor's disclosures concentrate on application-layer weaknesses including SQL injection, cross-site scripting, cross-site request forgery, and improper authentication rate-limiting—issues endemic to web applications handling user input and session state. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gestsup over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31646CRITICAL Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for | Apr 26, 2021 | 9.8 | 29 | NO | NO |
CVE-2026-22194HIGH GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authenticity of client requests. An | Jan 9, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-22197HIGH GestSup versions prior to 3.2.60 contain multiple SQL injection vulnerabilities in the asset list functionality. Multiple request parameters used to filter, search, or sort assets | Jan 9, 2026 | 8.1 | 25 | NO | NO |
CVE-2026-22196HIGH GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in ticket creation functionality. User-controlled input provided during ticket creation is incorporated into | Jan 9, 2026 | 8.1 | 25 | NO | NO |
CVE-2026-22195HIGH GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in the search bar functionality. User-controlled search input is incorporated into SQL queries without suffic | Jan 9, 2026 | 8.1 | 25 | NO | NO |
CVE-2026-22198MEDIUM GestSup versions prior to 3.2.60 contain a pre-authentication stored cross-site scripting (XSS) vulnerability in the API error logging functionality. By sending an API request with | Jan 9, 2026 | 6.1 | 21 | NO | NO |
CVE-2023-52059MEDIUM A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description text fie | Feb 13, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-52060MEDIUM A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request. | Feb 13, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gestsup.
Media articles that mention a CVE ID that affects a product developed by Gestsup — matched by CVE ID, not by vendor name.