Intercom operates a customer communication and engagement platform with a narrow product footprint but relatively broad deployment among SaaS and service-oriented businesses. Its vulnerability profile centers on authentication, request forgery, and input-handling classes typical of web-facing communication infrastructure, with a tendency toward serious severity outcomes. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Intercom over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-10817CRITICAL MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Service Server. | Aug 4, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-10818CRITICAL MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection settings of Terminal Agent and spoof the R | Aug 4, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-10816CRITICAL SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL commands via Relay Service Server. | Aug 4, 2017 | 9.8 | 27 | NO | NO |
CVE-2019-14365HIGH The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, | Nov 12, 2019 | 7.5 | 24 | NO | NO |
CVE-2017-10815HIGH MaLion for Windows 5.2.1 and earlier (only when "Remote Control" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when "Remote Control" is installed) allow remote attackers to | Aug 4, 2017 | 8.1 | 24 | NO | NO |
CVE-2014-3881MEDIUM Cross-site request forgery (CSRF) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to hijack the authentication of arbitrary users. | Jun 28, 2014 | 6.8 | 18 | NO | NO |
CVE-2017-10819MEDIUM MaLion for Mac 4.3.0 to 5.2.1 does not properly validate certificates, which may allow an attacker to eavesdrop on an encrypted communication. | Aug 4, 2017 | 5.9 | 16 | NO | NO |
CVE-2014-2006MEDIUM Cross-site scripting (XSS) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jun 28, 2014 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Intercom.
Media articles that mention a CVE ID that affects a product developed by Intercom — matched by CVE ID, not by vendor name.