Sysaid develops a focused portfolio of IT service-management and help-desk software serving mid-market and enterprise organizations, with versions spanning both cloud-hosted and on-premises deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong, recurring history of confirmed in-the-wild exploitation paired with frequent public exploit availability. The exposure recurs across its core product line and application programming interface through web-application and data-handling weakness classes including cross-site scripting, path traversal, SQL injection, and XML external entity injection—patterns characteristic of web-facing administrative interfaces that process untrusted input. Defenders should treat Sysaid advisories as high-priority, especially for internet-reachable instances, since the help-desk platform's access to asset inventory and credential repositories makes it a valuable target for post-compromise persistence and lateral movement. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sysaid over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47246CRITICAL In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in Novem | Nov 10, 2023 | 9.8 | 98 | YES | YES |
CVE-2025-2776CRITICAL SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrat | May 7, 2025 | 9.8 | 95 | YES | YES |
CVE-2025-2775HIGH SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator | May 7, 2025 | 7.5 | 91 | YES | YES |
CVE-2015-2996HIGH Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the fileName parameter to getG | Jun 8, 2015 | 8.5 | 89 | NO | YES |
CVE-2025-2777CRITICAL SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator ac | May 7, 2025 | 9.8 | 83 | NO | YES |
CVE-2015-2993HIGH SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to | Jun 8, 2015 | 7.5 | 67 | NO | YES |
CVE-2015-2997MEDIUM SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFile, as demonstrated by a large | Jun 8, 2015 | 5.0 | 61 | NO | YES |
CVE-2015-2994MEDIUM Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators to execute arbitrary code by uploading a file with a .jsp ext | Jun 8, 2015 | 6.5 | 61 | NO | YES |
CVE-2015-2995MEDIUM The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote attackers to upload and execute arbitrary files via a NULL byt | Jun 8, 2015 | 6.8 | 53 | NO | YES |
CVE-2015-2998MEDIUM SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensitive information, as demonstrated by decrypting the database | Jun 8, 2015 | 5.0 | 43 | NO | YES |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sysaid.
Media articles that mention a CVE ID that affects a product developed by Sysaid — matched by CVE ID, not by vendor name.