CVE Tools

Freescout-help-desk

63 CVEs tracked since 2025. Since May 2025, none of them reached CISA KEV.

Freescout-help-desk CVEs per month

May 2025 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Freescout-help-desk CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-05240
2025-064 or fewer
2025-075 or fewer
2025-084 or fewer
2025-094 or fewer
2025-104 or fewer
2025-114 or fewer
2025-125 or fewer
2026-015 or fewer
2026-025 or fewer
2026-037 or fewer
2026-04220
2026-0590
2026-067 or fewer
2026-0780
2026-088 or fewer
2026-099 or fewer

Products

The products that kept showing up in Freescout-help-desk's monthly top three, with their CVEs summed over those months.

  1. Freescout634 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Freescout-help-desk.

  1. CVE-2026-53596FreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)5.3
  2. CVE-2026-53595FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL9.4
  3. CVE-2026-53594FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path4.9
  4. CVE-2026-53593FreeScout Vulnerable to Authenticated Remote Code Execution via incomplete upload extension denylist (.pht) — bypass of CVE-2025-484718.8
  5. CVE-2026-53592FreeScout vulnerable to prototype pollution in getQueryParam4.6
  6. CVE-2026-53591FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmails8.6
  7. CVE-2026-48812FreeScout Allows Unauthenticated Access to Legacy Attachment Files7.5
  8. CVE-2026-45295FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation Enumeration via Open Tracking Endpoint6.5
  9. CVE-2026-45294FreeScout: User Account Enumeration via Password Reset Response Differentiation5.3
  10. CVE-2026-47123FreeScout: Agent Impersonation via Missing HMAC Verification on Notification Reply Message-ID Path7.5
  11. CVE-2026-48810FreeScout: Thread Edit Authorization Bypass via Missing Mailbox Check4.3
  12. CVE-2026-48811FreeScout: Thread Deletion Bypasses Mailbox Access Revocation4.3
  13. CVE-2026-41906FreeScout: Conversation Change-Customer Cross-Mailbox Authorization Bypass7.1
  14. CVE-2026-41905FreeScout vulnerable to SSRF via Helper::sanitizeRemoteUrl: redirect destination not re-validated, allowing internal HTTP / cloud-metadata access7.7
  15. CVE-2026-41904FreeScout Stored XSS vulnerability in mailbox auto-reply: payload reaches every customer's email client (no CSP), bypassing strip_tags validator with mixed text+HTML content7.6

The record

Peak rank
#41 in Apr 2026
Busiest month shown
May 2025, 24 CVEs
Months with a KEV entry
0 since May 2025
Monthly snapshots
4 since 2025
Freescout-help-desk's full record, month by month