Home/Product/freescout
Product

freescout

46 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-40565
< 1.8.213
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function in app/Misc
6.1MEDIUM
CVE-2026-40498
< 1.8.213
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access dia
9.8CRITICAL
CVE-2026-40497
< 1.8.213
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's Helper::stripDangerousTags()
8.1HIGH
CVE-2026-40496
< 1.8.213
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated u
9.1CRITICAL
CVE-2026-39384
< 1.8.212
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the l
7.6HIGH
CVE-2026-35584
< 1.8.212
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /thread/read
6.5MEDIUM
CVE-2026-34443
< 1.8.211
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in ap
5.3MEDIUM
CVE-2026-34442
< 1.8.211
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulat
5.4MEDIUM
CVE-2026-32754
< 1.8.209
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to St
9.3CRITICAL
CVE-2026-32753
< 1.8.209
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, bypasses of the
5.4MEDIUM
CVE-2026-32752
< 1.8.209
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the ThreadPolicy
NONE
CVE-2026-28289
< 1.8.207
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636
10.0CRITICAL
CVE-2026-27637
< 1.8.206
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAut
9.8CRITICAL
CVE-2026-27636
< 1.8.206
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file uplo
8.8HIGH
CVE-2025-58163
< 1.8.186
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.185 and earlier contain a deserial
8.8HIGH
CVE-2025-54366
< 1.8.86
FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1.8.185 and
8.8HIGH
CVE-2025-48880
< 1.8.181
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an administrative account is a deleti
6.6MEDIUM
CVE-2025-48875
< 1.8.181
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's incorrect validation of last_
5.4MEDIUM
CVE-2025-48489
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Sit
4.8MEDIUM
CVE-2025-48488
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, deleting the file .htaccess allows an atta
5.4MEDIUM
CVE-2025-48487
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when creating a translation of a phrase th
4.8MEDIUM
CVE-2025-48486
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the cross-site scripiting (XSS) vulnerabil
5.4MEDIUM
CVE-2025-48485
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Sit
5.4MEDIUM
CVE-2025-48484
< 1.8.178
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application is vulnerable to Cross-Sit
5.4MEDIUM
CVE-2025-48483
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Sit
5.4MEDIUM
CVE-2025-48482
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulnerability.
4.3MEDIUM
CVE-2025-48481
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated email invi
9.8CRITICAL
CVE-2025-48480
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an authorized user with the administrator
2.7LOW
CVE-2025-48479
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the laravel-translation-manager package do
2.7LOW
CVE-2025-48478
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, insufficient input validation during user
4.9MEDIUM
CVE-2025-48477
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application's logic requires the user
8.1HIGH
CVE-2025-48476
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user records using
8.8HIGH
CVE-2025-48475
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the System does not provide a check on whi
8.1HIGH
CVE-2025-48474
< 1.8.180
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application incorrectly checks user ac
8.1HIGH
CVE-2025-48473
< 1.8.179
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, when creating a conversation from a messag
4.3MEDIUM
CVE-2025-48472
< 1.8.179
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that the user
8.1HIGH
CVE-2025-48471
< 1.8.179
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, the application does not check or performs
9.8CRITICAL
CVE-2025-48390
< 1.8.178
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to code injection
7.2HIGH
CVE-2025-48389
< 1.8.178
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deserialization
7.2HIGH
CVE-2025-48388
< 1.8.178
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insufficient vali
6.5MEDIUM
CVE-2024-34698
< 1.8.139
FreeScout is a free, self-hosted help desk and shared mailbox. Versions of FreeScout prior to 1.8.139 contain a Prototype Pollutio
4.6MEDIUM
CVE-2024-34697
< 1.8.139
FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified in the Em
7.6HIGH
CVE-2024-29185
< 1.8.128
FreeScout is a self-hosted help desk and shared mailbox. Versions prior to 1.8.128 are vulnerable to OS Command Injection in the /
9.0CRITICAL
CVE-2024-29184
< 1.8.128
FreeScout is a self-hosted help desk and shared mailbox. A Stored Cross-Site Scripting (XSS) vulnerability has been identified wit
8.0HIGH
CVE-2024-28186
< 1.8.124
FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free Scout Appl
7.1HIGH
CVE-2024-1932
< 1.8.101
Unrestricted Upload of File with Dangerous Type in freescout-helpdesk/freescout
4.8MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin