Helpdesk
Vendor:
First CVE: Apr 20, 2026 · Active for under a year
5
Total CVEs
More Total CVEs than 77% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Helpdesk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 20, 2026
3 months ago
Most Recent CVE
Apr 20, 2026
95 days ago
CVE Severity & Scoring
Helpdesk5 CVEs
100%
All CVEs352,231 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required5 (100.0%)
Privileges Required
Low3 (60.0%)
High2 (40.0%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-23758MEDIUM GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript b | Apr 20, 2026 | 5.4 | 21 | NO | NO |
CVE-2026-23757MEDIUM GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly to SWIFT_Report::Create() withou | Apr 20, 2026 | 5.4 | 21 | NO | NO |
CVE-2026-23756MEDIUM GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Controller_Step.In | Apr 20, 2026 | 5.4 | 21 | NO | NO |
CVE-2026-23753MEDIUM GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality where the charset POST parameter is passed directly to SWIF | Apr 20, 2026 | 4.8 | 19 | NO | NO |
CVE-2026-23752MEDIUM GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated administrators to | Apr 20, 2026 | 4.8 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Helpdesk
Top CWEs
Versions
No cataloged versions.