Wyomind develops help-desk and support ticketing software, with the observed vulnerability surface concentrated in web-application input handling and file operations. The recurring weakness classes center on path traversal, cross-site scripting, and unrestricted file uploads, which are endemic to web-facing forms and document-management interfaces common to ticket-management systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wyomind over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33353CRITICAL Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment dir | Mar 8, 2023 | 9.8 | 29 | NO | NO |
CVE-2021-33352CRITICAL An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field. | Mar 8, 2023 | 9.8 | 29 | NO | NO |
CVE-2021-33351CRITICAL Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in | Mar 8, 2023 | 9.0 | 26 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wyomind.
Media articles that mention a CVE ID that affects a product developed by Wyomind — matched by CVE ID, not by vendor name.