Freescout-Help-Desk Freescout vulnerabilities
69 known vulnerabilities affecting freescout-help-desk/freescout.
Total CVEs
69
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH26MEDIUM32LOW2
Vulnerabilities
Page 3 of 4
CVE-2025-48880P4MEDIUMCVSS 6.6fixed in 1.8.1812025-05-30
CVE-2025-48880 [MEDIUM] CWE-362 CVE-2025-48880: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an admi
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an administrative account is a deleting a user, there is the the possibility of a race condition occurring. This issue has been patched in version 1.8.181.
nvd
CVE-2026-40592P4MEDIUMCVSS 5.9fixed in 1.8.2142026-04-21
CVE-2026-40592 [MEDIUM] CWE-862 CVE-2026-40592: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-sen
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}` checks only whether the current user can view the parent conversation. It does not verify that the current user created the reply being undone. In a shared mailbox, one agent can therefore recall anot
nvd
CVE-2026-34442P4MEDIUMCVSS 6.1fixed in 1.8.2112026-03-31
CVE-2026-34442 [MEDIUM] CWE-20 CVE-2026-34442: FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary domain into generated absolute URLs. This leads to External Resource Loading and Open Redirect behavior. When the appl
nvd
CVE-2026-45294P4MEDIUMCVSS 5.3fixed in 1.8.2192026-05-29
CVE-2026-45294 [MEDIUM] CWE-203 CVE-2026-45294: FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219,
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses depending on whether the submitted email address belongs to an existing user account, allowing unauthenticated attackers to enumerate valid helpdesk agent email addresses. This vulnerabi
nvd
CVE-2026-32753P4MEDIUMCVSS 5.4fixed in 1.8.2092026-03-19
CVE-2026-32753 [MEDIUM] CWE-80 CVE-2026-32753: FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.2
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, bypasses of the attachment view logic and SVG sanitizer make it possible to upload and render an SVG that runs malicious JavaScript. An extension of .png with content type of image/svg+xml is allowed, and a fallback mechanism on invalid X
nvd
CVE-2026-53594P4MEDIUMCVSS 4.9fixed in 1.8.2242026-07-20
CVE-2026-53594 [MEDIUM] CWE-22 CVE-2026-53594: FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Mana
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Logs` feature uses the bundled `rap2hpoutre/laravel-log-viewer` override to decrypt a user-supplied file identifier and then pass the resolved path to Laravel's download response. Prior to version 1.8.224, the path resolution logic ac
nvd
CVE-2026-40565P4MEDIUMCVSS 6.1fixed in 1.8.2132026-04-21
CVE-2026-40565 [MEDIUM] CWE-79 CVE-2026-40565: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function in app/Misc/Helper.php converts plain-text URLs in email bodies into HTML anchor tags without escaping double-quote characters (") in the URL. HTMLPurifier (called first via getCleanBody()) preserves literal " characters in text nodes
nvd
CVE-2026-34443P4MEDIUMCVSS 5.3fixed in 1.8.2112026-03-31
CVE-2026-34443 [MEDIUM] CWE-918 CVE-2026-34443: FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in app/Misc/Helper.php checks whether the input IP contains a / character. Plain IP addresses never contain /, so the function always returns false without checking any CIDR ranges. The entire 10.0.0.0/8 and 172.16.0.0/12 priva
nvd
CVE-2026-53596P4MEDIUMCVSS 5.3fixed in 1.8.2242026-07-20
CVE-2026-53596 [MEDIUM] CWE-400 CVE-2026-53596: FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce rate limiting on the file upload endpoint. Any user can flood the server with upload requests, leading to database overload and potential denial of service for all users. Version 1.8.224 cont
nvd
CVE-2025-48488P4MEDIUMCVSS 5.4fixed in 1.8.1802025-05-30
CVE-2025-48488 [MEDIUM] CWE-79 CVE-2025-48488: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, deleting the
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, deleting the file .htaccess allows an attacker to upload an HTML file containing malicious JavaScript code to the server, which can result in a Cross-Site Scripting (XSS) vulnerability. This issue has been patched in version 1.8.180.
nvd
CVE-2025-48486P4MEDIUMCVSS 5.4fixed in 1.8.1802025-05-30
CVE-2025-48486 [MEDIUM] CWE-79 CVE-2025-48486: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the cross-si
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the cross-site scripiting (XSS) vulnerability is caused by the lack of input validation and sanitization in both \Session::flash and __, allowing user input to be executed without proper filtering. This issue has been patched in version 1.8.180.
nvd
CVE-2025-48484P4MEDIUMCVSS 5.4fixed in 1.8.1782025-05-30
CVE-2025-48484 [MEDIUM] CWE-79 CVE-2025-48484: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the applicat
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data in the conversation POST data body. This issue has been patched in version 1.8.178.
nvd
CVE-2025-48485P4MEDIUMCVSS 5.4fixed in 1.8.1802025-05-30
CVE-2025-48485 [MEDIUM] CWE-79 CVE-2025-48485: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the applicat
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data when an authenticated user updates the profile of an arbitrary customer. This issue has been patched in version 1.8.180.
nvd
CVE-2025-48875P4MEDIUMCVSS 5.4fixed in 1.8.1812025-05-30
CVE-2025-48875 [MEDIUM] CWE-79 CVE-2025-48875: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's incorrect validation of last_name and first_name during profile data updates allows for the injection of arbitrary JavaScript code, which will be executed in a flesh-message when the data is deleted, potentially leading to a Cross-Site Scripting (XSS)
nvd
CVE-2025-48478P4MEDIUMCVSS 4.9fixed in 1.8.1802025-05-30
CVE-2025-48478 [MEDIUM] CWE-841 CVE-2025-48478: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, insufficient
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, insufficient input validation during user creation has resulted in a mass assignment vulnerability, allowing an attacker to manipulate all fields of the object, which are enumerated in the $fillable array (the User object), when creating a new user. This issue ha
nvd
CVE-2026-53592P4MEDIUMCVSS 4.6fixed in 1.8.2232026-07-20
CVE-2026-53592 [MEDIUM] CWE-1321 CVE-2026-53592: FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollu
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in the `getQueryParam` function `/public/js/main.js` and was addressed in version 1.8.139 by blocking URL query keys matching the pattern `__proto__`. However, this mitigation is incomplete: it only filters top-level `__proto__` keys a
nvd
CVE-2026-41194P4MEDIUMCVSS 5.4fixed in 1.8.2152026-04-21
CVE-2026-41194 [MEDIUM] CWE-352 CVE-2026-41194: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect action is implemented as `GET /mailbox/oauth-disconnect/{id}/{in_out}/{provider}`. It removes stored OAuth metadata from the mailbox and then redirects. Because it is a GET route, no CSRF token is required and the action can be trigger
nvd
CVE-2026-48811P4MEDIUMCVSS 4.3fixed in 1.8.2212026-05-29
CVE-2026-48811 [MEDIUM] CWE-862 CVE-2026-48811: FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221,
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a non-admin user to permanently delete an internal note (private thread) from any conversation, even after that user's access to the mailbox containing the conversation has been revoked. The ThreadPolicy::delete authorization policy
nvd
CVE-2025-48483P4MEDIUMCVSS 5.4fixed in 1.8.1802025-05-30
CVE-2025-48483 [MEDIUM] CWE-79 CVE-2025-48483: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the applicat
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data during mail signature sanitization. An attacker can inject arbitrary HTML code, including JavaScript scripts, into the page pr
nvd
CVE-2025-48473P4MEDIUMCVSS 4.3fixed in 1.8.1792025-05-29
CVE-2025-48473 [MEDIUM] CWE-863 CVE-2025-48473: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, when creatin
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, when creating a conversation from a message in another conversation, there is no check to ensure that the user has the ability to view this message. Thus, the user can view arbitrary messages from other mailboxes or from other conversations to which they do not h
nvd