Getawesomesupport maintains a focused product line centered on its Awesome Support helpdesk and ticketing platform, which serves small- to medium-sized businesses requiring customer-facing support infrastructure. The vendor's vulnerability exposure clusters around application-layer weaknesses endemic to web-facing support systems: missing authorization checks, cross-site scripting, cross-site request forgery, path traversal, and argument-handling flaws that reflect the challenges of building multi-tenant, user-accessible web applications. These weakness classes, spanning authentication bypass, input sanitization, session management, and file-access controls, recur across the platform and represent durable structural risks rather than isolated incidents. Defenders deploying this product should prioritize access controls, input validation testing, and network segmentation for the support tier; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getawesomesupport over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-30539CRITICAL Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7. | Jun 9, 2024 | 9.8 | 31 | NO | NO |
CVE-2024-35741HIGH Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7. | Jun 10, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-0594HIGH The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all | Feb 10, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-51538HIGH Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin.This issue affects Awesome Support – WordPress HelpDes | Jan 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-5355HIGH The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on th | Nov 6, 2023 | 8.1 | 23 | NO | NO |
CVE-2022-3511MEDIUM The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileg | Nov 28, 2022 | 6.5 | 23 | NO | NO |
CVE-2023-48323HIGH Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects A | Nov 30, 2023 | 8.8 | 21 | NO | NO |
CVE-2022-38073MEDIUM Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Support plugin <= 6.0.7 at WordPress. | Sep 21, 2022 | 5.4 | 20 | NO | NO |
CVE-2021-36919MEDIUM Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (versions <= 6.0.6), vulnerable parameters (&id, &assignee). | Nov 26, 2021 | 5.4 | 20 | NO | NO |
CVE-2015-9318HIGH The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies. | Aug 20, 2019 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getawesomesupport.
Media articles that mention a CVE ID that affects a product developed by Getawesomesupport — matched by CVE ID, not by vendor name.