Usedesk is a customer-support and help-desk platform whose vulnerability footprint centers on web application input-handling issues, specifically cross-site scripting and injection flaws in the core product. These weakness classes are typical of web-facing applications where output generation and downstream component interaction require careful input neutralization; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Usedesk over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-49214CRITICAL Usedesk before 1.7.57 allows chat template injection. | Nov 23, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-49215MEDIUM Usedesk before 1.7.57 allows filter reflected XSS. | Nov 23, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-49216MEDIUM Usedesk before 1.7.57 allows profile stored XSS. | Nov 23, 2023 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Usedesk.
Media articles that mention a CVE ID that affects a product developed by Usedesk — matched by CVE ID, not by vendor name.