Freescout-Help-Desk Freescout vulnerabilities
69 known vulnerabilities affecting freescout-help-desk/freescout.
Total CVEs
69
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH26MEDIUM32LOW2
Vulnerabilities
Page 4 of 4
CVE-2026-40590P4MEDIUMCVSS 4.3fixed in 1.8.2142026-04-21
CVE-2026-40590 [MEDIUM] CWE-639 CVE-2026-40590: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change C
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal exposes a “Create a new customer” flow via POST /customers/ajax with action=create. Under limited visibility, the endpoint drops unique-email validation. If the supplied email already belongs to a hidden customer, Customer::create() reus
nvd
CVE-2026-41183P4MEDIUMCVSS 4.3fixed in 1.8.2152026-04-21
CVE-2026-41183 [MEDIUM] CWE-200 CVE-2026-41183: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned-only restriction is applied to direct conversation view and folder queries, but not to non-folder query builders. Global search and the AJAX filter path still reveal conversations that should be hidden. Version 1.8.215 fixes the vulnerability.
nvd
CVE-2026-48810P4MEDIUMCVSS 4.3fixed in 1.8.2212026-05-29
CVE-2026-48810 [MEDIUM] CWE-285 CVE-2026-48810: FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221,
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, while investigating the ThreadPolicy::delete issue reported previously, the same missing mailbox membership check was found in the sibling ThreadPolicy::edit method. A user with the PERM_EDIT_CONVERSATIONS permission who created a message or internal
nvd
CVE-2026-40566P4MEDIUMCVSS 4.1fixed in 1.8.2132026-04-21
CVE-2026-40566 [MEDIUM] CWE-918 CVE-2026-40566: FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Serve
FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forgery (SSRF) vulnerability in the IMAP/SMTP connection test functionality of FreeScout's `MailboxesController`. Three AJAX actions `fetch_test` (line 731), `send_test` (line 682), and `imap_folders` (line 773) in `app/Http/Controllers
nvd
CVE-2025-48482P4MEDIUMCVSS 4.3fixed in 1.8.1802025-05-30
CVE-2025-48482 [MEDIUM] CWE-841 CVE-2025-48482: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a m
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulnerability. The Customer object is updated using the fill() method, which processes fields such as channel and channel_id. However, the fill() method is called with all client-provided data, including unexpected values for channel an
nvd
CVE-2025-48487P4MEDIUMCVSS 4.8fixed in 1.8.1802025-05-30
CVE-2025-48487 [MEDIUM] CWE-79 CVE-2025-48487: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when creatin
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when creating a translation of a phrase that appears in a flash-message after a completed action, it is possible to inject a payload to exploit XSS vulnerability. This issue has been patched in version 1.8.180.
nvd
CVE-2025-48489P4MEDIUMCVSS 4.8fixed in 1.8.1802025-05-30
CVE-2025-48489 [MEDIUM] CWE-79 CVE-2025-48489: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the applicat
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to insufficient data validation and sanitization during data reception. This issue has been patched in version 1.8.180.
nvd
CVE-2025-48479P4LOWCVSS 2.7fixed in 1.8.1802025-05-30
CVE-2025-48479 [LOW] CWE-841 CVE-2025-48479: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the laravel-
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the laravel-translation-manager package does not correctly validate user input, enabling the deletion of any directory, given sufficient access rights. This issue has been patched in version 1.8.180.
nvd
CVE-2025-48480P4LOWCVSS 2.7fixed in 1.8.1802025-05-30
CVE-2025-48480 [LOW] CWE-841 CVE-2025-48480: FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an authorize
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an authorized user with the administrator role or with the privilege User::PERM_EDIT_USERS can create a user, specifying the path to the user's avatar ../.htaccess during creation, and then delete the user's avatar, resulting in the deletion of the file .htaccess in
nvd
← Previous4 / 4