Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sysaid

First CVE: Jan 2, 2015Active for: 12 yearsTotal CVEs: 40
63.5
VTI Score
TOP TARGET

Sysaid develops a focused portfolio of IT service-management and help-desk software serving mid-market and enterprise organizations, with versions spanning both cloud-hosted and on-premises deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong, recurring history of confirmed in-the-wild exploitation paired with frequent public exploit availability. The exposure recurs across its core product line and application programming interface through web-application and data-handling weakness classes including cross-site scripting, path traversal, SQL injection, and XML external entity injection—patterns characteristic of web-facing administrative interfaces that process untrusted input. Defenders should treat Sysaid advisories as high-priority, especially for internet-reachable instances, since the help-desk platform's access to asset inventory and credential repositories makes it a valuable target for post-compromise persistence and lateral movement. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
40
Total CVEs
More Total CVEs than 98% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
7.5%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Sysaid over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 2, 2015
11 years ago
Most Recent CVE
May 7, 2025
443 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-47246CRITICAL
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in Novem
Nov 10, 20239.898YESYES
CVE-2025-2776CRITICAL
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrat
May 7, 20259.895YESYES
CVE-2025-2775HIGH
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator
May 7, 20257.591YESYES
CVE-2015-2996HIGH
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the fileName parameter to getG
Jun 8, 20158.589NOYES
CVE-2025-2777CRITICAL
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator ac
May 7, 20259.883NOYES
CVE-2015-2993HIGH
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to
Jun 8, 20157.567NOYES
CVE-2015-2997MEDIUM
SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFile, as demonstrated by a large
Jun 8, 20155.061NOYES
CVE-2015-2994MEDIUM
Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators to execute arbitrary code by uploading a file with a .jsp ext
Jun 8, 20156.561NOYES
CVE-2015-2995MEDIUM
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote attackers to upload and execute arbitrary files via a NULL byt
Jun 8, 20156.853NOYES
CVE-2015-2998MEDIUM
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensitive information, as demonstrated by decrypting the database
Jun 8, 20155.043NOYES
View all 40 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products40 CVEs
55%
23%
23%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network30 (75.0%)
Unknown10 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (75.0%)
High0 (0.0%)
Unknown10 (25.0%)
User Interaction
None21 (52.5%)
Unknown10 (25.0%)
Required9 (22.5%)
Privileges Required
Low8 (20.0%)
High1 (2.5%)
None21 (52.5%)
Unknown10 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (40 CVEs).

CISA KEV
3 CVEs
7.5% of CVEs· 100th percentile
Metasploit
6 CVEs
15.0% of CVEs· 99th percentile
Nuclei
7 CVEs
17.5% of CVEs· 97th percentile
ExploitDB
10 CVEs
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sysaid.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sysaid — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sysaid's Products

View all 3 CNAs →

Top CWEs