Kayako maintains a customer-support platform spanning products such as eSupport, SupportSuite, and Kayako Fusion that are deployed across service organizations for ticketing, knowledge management, and chat functionality. Despite a narrow product portfolio, the vendor's disclosures are more prominent than most in the landscape and frequently acquire public exploit code, reflecting the appeal of customer-service platforms as targets for credential theft, data exfiltration, and operational disruption. The recurring vulnerability patterns center on web-application and data-handling weaknesses: cross-site scripting, SQL injection, sensitive information exposure, and resource-consumption flaws that are endemic to multi-tenant web services handling customer interactions. Defenders should treat Kayako deployments as high-value targets for patching, prioritize internet-exposed instances, and monitor for post-authentication abuse vectors given the sensitive customer data these platforms typically store. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kayako over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2912HIGH SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the _a parameter in a downloads action. | Jul 28, 2010 | 7.5 | 32 | NO | YES |
CVE-2010-2911HIGH SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a viewnews action. | Jul 28, 2010 | 7.5 | 31 | NO | YES |
CVE-2008-3701MEDIUM SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and earlier allows remote authenticated users to execute arbitrary SQL commands via the customfieldlin | Aug 15, 2008 | 6.5 | 26 | NO | YES |
CVE-2005-2461MEDIUM Multiple SQL injection vulnerabilities in the calendar feature in Kayako liveResponse 2.x allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) date para | Dec 31, 2005 | 6.4 | 26 | NO | YES |
CVE-2004-1412MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.x allows remote attackers to inject arbitrary web script or HTML via the searchm parameter. | Dec 31, 2004 | 4.3 | 26 | NO | YES |
CVE-2005-2460MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Kayako liveResponse 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter or (2) n | Dec 31, 2005 | 5.8 | 25 | NO | YES |
CVE-2012-3233MEDIUM Cross-site scripting (XSS) vulnerability in __swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in Kayako Fusion 4.40.1148, and possibly before 4.50.1581, allows rem | Sep 15, 2012 | 4.3 | 24 | NO | YES |
CVE-2008-3700MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the sessionid p | Aug 15, 2008 | 4.3 | 22 | NO | YES |
CVE-2004-1413MEDIUM Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticket | Dec 31, 2004 | 5.0 | 22 | NO | YES |
CVE-2008-4761MEDIUM Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.20.2 allows remote attackers to inject arbitrary web script | Oct 28, 2008 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kayako.
Media articles that mention a CVE ID that affects a product developed by Kayako — matched by CVE ID, not by vendor name.