Trudesk Project maintains a single, focused help-desk and ticketing application that serves as a customer-interaction platform for service organizations, earning prominence among vulnerability-tracked software despite its narrow product scope. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, while the application's exposure concentrates around input-handling and privilege-management weaknesses including integer overflow, cross-site scripting, file-upload validation, and improper access control. These weakness classes reflect the complexity inherent to a web-facing application that processes untrusted user input and manages role-based permissions across customer and support interactions. Defenders should treat Trudesk advisories as requiring timely evaluation, particularly for internet-exposed instances; current exploitation status and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trudesk Project over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2023CRITICAL Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4. | Jun 20, 2022 | 9.8 | 33 | NO | NO |
CVE-2022-2128CRITICAL Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4. | Jun 20, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-1770HIGH Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2. | May 20, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-1752HIGH Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2. | May 21, 2022 | 8.0 | 26 | NO | NO |
CVE-2022-1775CRITICAL Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2. | May 20, 2022 | 9.8 | 24 | NO | NO |
CVE-2022-1803MEDIUM Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2. | May 20, 2022 | 6.9 | 24 | NO | NO |
CVE-2022-1808HIGH Execution with Unnecessary Privileges in GitHub repository polonel/trudesk prior to 1.2.3. | May 31, 2022 | 8.8 | 23 | NO | NO |
CVE-2022-1754MEDIUM Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.2. | May 20, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-1947MEDIUM Use of Incorrect Operator in GitHub repository polonel/trudesk prior to 1.2.3. | May 31, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-1728MEDIUM Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack fo | May 16, 2022 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trudesk Project.
Media articles that mention a CVE ID that affects a product developed by Trudesk Project — matched by CVE ID, not by vendor name.