Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kayako

First CVE: Dec 31, 2004Active for: 22 yearsTotal CVEs: 26
26.4
VTI Score
Low

Kayako maintains a customer-support platform spanning products such as eSupport, SupportSuite, and Kayako Fusion that are deployed across service organizations for ticketing, knowledge management, and chat functionality. Despite a narrow product portfolio, the vendor's disclosures are more prominent than most in the landscape and frequently acquire public exploit code, reflecting the appeal of customer-service platforms as targets for credential theft, data exfiltration, and operational disruption. The recurring vulnerability patterns center on web-application and data-handling weaknesses: cross-site scripting, SQL injection, sensitive information exposure, and resource-consumption flaws that are endemic to multi-tenant web services handling customer interactions. Defenders should treat Kayako deployments as high-value targets for patching, prioritize internet-exposed instances, and monitor for post-authentication abuse vectors given the sensitive customer data these platforms typically store. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
4.8
Avg CVSS Score
Higher Avg CVSS Score than 10% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Kayako over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Sep 6, 2022
1,417 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-2912HIGH
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the _a parameter in a downloads action.
Jul 28, 20107.532NOYES
CVE-2010-2911HIGH
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a viewnews action.
Jul 28, 20107.531NOYES
CVE-2008-3701MEDIUM
SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and earlier allows remote authenticated users to execute arbitrary SQL commands via the customfieldlin
Aug 15, 20086.526NOYES
CVE-2005-2461MEDIUM
Multiple SQL injection vulnerabilities in the calendar feature in Kayako liveResponse 2.x allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) date para
Dec 31, 20056.426NOYES
CVE-2004-1412MEDIUM
Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.x allows remote attackers to inject arbitrary web script or HTML via the searchm parameter.
Dec 31, 20044.326NOYES
CVE-2005-2460MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Kayako liveResponse 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter or (2) n
Dec 31, 20055.825NOYES
CVE-2012-3233MEDIUM
Cross-site scripting (XSS) vulnerability in __swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in Kayako Fusion 4.40.1148, and possibly before 4.50.1581, allows rem
Sep 15, 20124.324NOYES
CVE-2008-3700MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the sessionid p
Aug 15, 20084.322NOYES
CVE-2004-1413MEDIUM
Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticket
Dec 31, 20045.022NOYES
CVE-2008-4761MEDIUM
Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.20.2 allows remote attackers to inject arbitrary web script
Oct 28, 20084.321NOYES
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
12%
81%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (3.8%)
Unknown25 (96.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (3.8%)
High0 (0.0%)
Unknown25 (96.2%)
User Interaction
None0 (0.0%)
Unknown25 (96.2%)
Required1 (3.8%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (3.8%)
Unknown25 (96.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
14 CVEs
53.8% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kayako.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kayako — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kayako's Products

View all 1 CNAs →

Top CWEs