Helpdeskz is a help-desk ticketing platform that, despite a narrow product footprint, maintains a presence in deployment environments where web-application security is critical. The recurring vulnerability signal centers on cross-site scripting weaknesses in the platform's web interface, reflecting input-handling challenges common to customer-facing ticketing applications. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Helpdeskz over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2078MEDIUM A Cross-Site Scripting (XSS) vulnerability has been found in HelpDeskZ affecting version 2.0.2 and earlier. This vulnerability could allow an attacker to send a specially crafted J | Mar 1, 2024 | 6.1 | 18 | NO | NO |
CVE-2022-31400MEDIUM A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injec | Jun 13, 2022 | 4.8 | 18 | NO | NO |
CVE-2022-31398MEDIUM A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injecte | Jun 13, 2022 | 4.8 | 18 | NO | NO |
CVE-2024-46226MEDIUM A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious | Feb 26, 2025 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Helpdeskz.
Media articles that mention a CVE ID that affects a product developed by Helpdeskz — matched by CVE ID, not by vendor name.