Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-53596: CWE-400: Uncontrolled Resource Consumption in freescout-help-desk freescoutCVE-2026-53596
0

FreeScout versions prior to 1.8.224 have a vulnerability in the file upload endpoint where rate limiting is not enforced. This allows any user to send excessive upload requests, potentially overloading the database and causing denial of service. The issue is fixed in version 1.8.224.

Join the discussion
CVE-2026-53595: CWE-178: Improper Handling of Case Sensitivity in freescout-help-desk freescoutCVE-2026-53595
0

FreeScout versions prior to 1.8.224 contain a critical vulnerability in the user setup endpoint that allows an unauthenticated attacker to overwrite the email and password of the lowest-id activated user account and authenticate as that user. This occurs due to improper handling of case sensitivity and trailing spaces in the invite_hash field on MySQL/MariaDB, combined with a flawed decryption check that allows bypassing expiry validation. The vulnerability is fixed in version 1.8.224.

Join the discussion
CVE-2026-53594: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in freescout-help-desk freescoutCVE-2026-53594
0

FreeScout versions prior to 1.8.224 contain a path traversal vulnerability in the App Logs feature. This flaw allows an attacker with access to the App Logs route and the ability to forge a valid Laravel-encrypted parameter to download arbitrary files readable by the PHP process, bypassing intended directory restrictions. The vulnerability is fixed in version 1.8.224.

Join the discussion
CVE-2026-53593: CWE-434: Unrestricted Upload of File with Dangerous Type in freescout-help-desk freescoutCVE-2026-53593
0

FreeScout versions prior to 1.8.224 have an incomplete denylist for dangerous file uploads, missing the .pht extension. Authenticated users can upload .pht files, which are executed by default Apache PHP handlers, allowing remote code execution as the web server user. This vulnerability bypasses a previous fix that did not cover .pht files. Version 1.8.224 includes an updated fix to address this issue.

Join the discussion
CVE-2026-53591: CWE-287: Improper Authentication in freescout-help-desk freescoutCVE-2026-53591
0

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public address with a crafted `In-Reply-To` header. No credentials, tokens, or prior access are required. The injected message is rendered in the agent UI as a legitimate customer reply, the conversation is automatically reopened, and the `last_reply_from` field is set to the attacker's identity. Version 1.8.223 contains a fix.

Join the discussion
CVE-2026-48812: CWE-287: Improper Authentication in freescout-help-desk freescoutCVE-2026-48812
0

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download route skips token authentication for any attachment whose `token_type` is set to `1` (`TOKEN_TYPE_LEGACY`). Because this route is unauthenticated and the file path is deterministic, an unauthenticated remote attacker can download any attachment that was created by an older version of FreeScout without possessing a valid token or session. Version 1.8.221 contains a fix.

Join the discussion
CVE-2026-45295: CWE-639: Authorization Bypass Through User-Controlled Key in freescout-help-desk freescoutCVE-2026-45295
0

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/read/{conversation_id}/{thread_id}` allows unauthenticated attackers to enumerate valid conversation and thread IDs, and modify thread state (`opened_at` timestamp) without any authentication. Version 1.8.219 patches the issue.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:github/freescout-help-desk/freescout
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses