CVE-2026-40497
- EPSS -
- Veröffentlicht 21.04.2026 01:45:55
- Zuletzt bearbeitet 21.04.2026 03:16:08
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDangerousTags()` removes `<script>`, `<form>`, `<iframe>`, `<object>` but does NOT strip `<style>` tags. The mailbox signature field is ...
CVE-2026-40496
- EPSS -
- Veröffentlicht 21.04.2026 01:38:50
- Zuletzt bearbeitet 21.04.2026 02:16:08
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY + attachment_id + size)`. Since attachment_id is sequential and size c...
CVE-2026-35584
- EPSS 0.06%
- Veröffentlicht 07.04.2026 16:07:33
- Zuletzt bearbeitet 16.04.2026 18:57:29
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /thread/read/{conversation_id}/{thread_id} does not require authentication and does not validate whether the given thread_id belongs...
CVE-2026-39384
- EPSS 0.03%
- Veröffentlicht 07.04.2026 16:05:16
- Zuletzt bearbeitet 09.04.2026 17:16:28
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the limit_user_customer_visibility parameter into account when merging customers. This vulnerability is fixed in 1.8.212.
CVE-2026-34442
- EPSS 0.08%
- Veröffentlicht 31.03.2026 21:28:19
- Zuletzt bearbeitet 01.04.2026 19:49:03
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary domain into gen...
CVE-2026-34443
- EPSS 0.05%
- Veröffentlicht 31.03.2026 21:28:16
- Zuletzt bearbeitet 13.04.2026 15:14:59
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in app/Misc/Helper.php checks whether the input IP contains a / character. Plain IP addresses never contain /, so the functio...
CVE-2026-32754
- EPSS 0.06%
- Veröffentlicht 19.03.2026 21:35:17
- Zuletzt bearbeitet 23.03.2026 19:14:38
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email notification templates. Incoming email bodies are stored in th...
CVE-2026-32753
- EPSS 0.03%
- Veröffentlicht 19.03.2026 21:26:09
- Zuletzt bearbeitet 23.03.2026 19:25:21
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, bypasses of the attachment view logic and SVG sanitizer make it possible to upload and render an SVG that runs malicious JavaScript. An ...
CVE-2026-32752
- EPSS 0.04%
- Veröffentlicht 19.03.2026 21:21:54
- Zuletzt bearbeitet 23.03.2026 19:30:28
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the ThreadPolicy::edit() method contains a broken access control vulnerability that allows any authenticated user (regardless of role or...
CVE-2026-28289
- EPSS 17.68%
- Veröffentlicht 03.03.2026 22:59:08
- Zuletzt bearbeitet 11.03.2026 19:29:44
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Exec...