Logon's vulnerability profile centers on a knowledge-base support product and reflects weakness classes typical of web-facing applications handling user access and data: missing authorization controls, CSV injection via formula elements, and open-redirect vulnerabilities. These inputs suggest a modest footprint where defenders should prioritize access-control review and input-sanitization practices when deploying or customizing this support tier. Current exposure counts and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Logon over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8548HIGH The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on severa | Oct 1, 2024 | 8.1 | 24 | NO | NO |
CVE-2023-25983HIGH Improper Neutralization of Formula Elements in a CSV File vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.5.84. | Nov 7, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-8632MEDIUM The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the | Oct 1, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-33589MEDIUM Missing Authorization vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.6.0. | Apr 29, 2024 | 6.5 | 19 | NO | NO |
CVE-2025-24741MEDIUM URL Redirection to Untrusted Site ('Open Redirect') vulnerability in LOGON KB Support kb-support.This issue affects KB Support: from n/a through <= 1.6.7. | Jan 27, 2025 | 6.1 | 18 | NO | NO |
CVE-2023-37890MEDIUM Missing Authorization vulnerability in WPOmnia KB Support – WordPress Help Desk and Knowledge Base allows Accessing Functionality Not Properly Constrained by ACLs. Users with a rol | Nov 30, 2023 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Logon.
Media articles that mention a CVE ID that affects a product developed by Logon — matched by CVE ID, not by vendor name.