Hesk is a help desk and ticketing system with a niche but recurrent vulnerability profile centered on the core product and characterized by web application input-handling and information-disclosure issues such as cross-site scripting and improper exposure of sensitive data. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hesk over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13897MEDIUM HESK before 3.1.10 allows reflected XSS. | Jun 7, 2020 | 6.1 | 22 | NO | NO |
CVE-2011-5287MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in HESK before 2.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) hesk_settings[tmp_title] or (2) h | Jan 1, 2015 | 4.3 | 17 | NO | NO |
CVE-2011-3743MEDIUM Hesk 2.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by in | Sep 23, 2011 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hesk.
Media articles that mention a CVE ID that affects a product developed by Hesk — matched by CVE ID, not by vendor name.