deskpro records
13 published records for vendor deskpro.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-269 Improper Privilege Management2
- CWE-862 Missing Authorization2
- CWE-502 Deserialization of Untrusted Data1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2020-11465No exploit | An issue was discovered in Deskpro before 2019.8.0.deskpro · deskpro · CWE-862 | High8.8 | — | 1.9% | Apr 1, 2020 |
31Monitor | CVE-2020-11463No exploit | An issue was discovered in Deskpro before 2019.8.0.deskpro · deskpro · CWE-862 | High7.5 | — | 1.8% | Apr 1, 2020 |
29Monitor | CVE-2020-11467No exploit | An issue was discovered in Deskpro before 2019.8.0.deskpro · deskpro · CWE-502 | High7.2 | — | 4.0% | Apr 1, 2020 |
28Monitor | CVE-2021-35391No exploit | Server Side Request Forgery vulnerability found in Deskpro Support Desk v2021.21.6 allows attackers to execute arbitrary code via a crafted deskpro · deskpro · CWE-918 | High7.2 | — | 1.0% | Jul 21, 2023 |
27Monitor | CVE-2006-6159No exploit | Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in DeskPRO 2.0.0 and 2.0.1 allow remote attackers to inject arbitrary wdeskpro · deskpro · CWE-79 | Medium6.8 | — | 1.4% | Nov 28, 2006 |
21Monitor | CVE-2020-28722No exploit | Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to andeskpro · deskpro · CWE-79 | Medium5.4 | — | 0.6% | May 12, 2021 |
21Monitor | CVE-2021-36696No exploit | Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social medeskpro · deskpro · CWE-79 | Medium5.4 | — | 0.6% | Sep 7, 2021 |
21Monitor | CVE-2021-36695No exploit | Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the downldeskpro · deskpro · CWE-79 | Medium5.4 | — | 0.6% | Sep 8, 2021 |
20Monitor | CVE-2003-0874No exploit | Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized deskpro · deskpro | Medium5.0 | — | 1.4% | Nov 17, 2003 |
18Monitor | CVE-2007-2011Proof of concept | Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via thdeskpro · deskpro | Medium4.3 | — | 1.9% | Apr 12, 2007 |
17Monitor | CVE-2020-11466No exploit | An issue was discovered in Deskpro before 2019.8.0.deskpro · deskpro · CWE-269 | Medium4.3 | — | 1.2% | Apr 1, 2020 |
17Monitor | CVE-2020-11464No exploit | An issue was discovered in Deskpro before 2019.8.0.deskpro · deskpro · CWE-269 | Medium4.3 | — | 1.2% | Apr 1, 2020 |
17Monitor | CVE-2007-1012No exploit | Cross-site scripting (XSS) vulnerability in faq.php in DeskPRO 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the deskpro · deskpro · CWE-79 | Medium4.3 | — | 1.1% | Feb 21, 2007 |
- CVE-2020-1146536Monitor
An issue was discovered in Deskpro before 2019.8.0.
HighCVSS 8.8No exploitEPSS 2%deskpro · deskproApr 1, 2020
- CVE-2020-1146331Monitor
An issue was discovered in Deskpro before 2019.8.0.
HighCVSS 7.5No exploitEPSS 2%deskpro · deskproApr 1, 2020
- CVE-2020-1146729Monitor
An issue was discovered in Deskpro before 2019.8.0.
HighCVSS 7.2No exploitEPSS 4%deskpro · deskproApr 1, 2020
- CVE-2021-3539128Monitor
Server Side Request Forgery vulnerability found in Deskpro Support Desk v2021.21.6 allows attackers to execute arbitrary code via a crafted
HighCVSS 7.2No exploitEPSS 1%deskpro · deskproJul 21, 2023
- CVE-2006-615927Monitor
Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in DeskPRO 2.0.0 and 2.0.1 allow remote attackers to inject arbitrary w
MediumCVSS 6.8No exploitEPSS 1%deskpro · deskproNov 28, 2006
- CVE-2020-2872221Monitor
Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an
MediumCVSS 5.4No exploitEPSS 1%deskpro · deskproMay 12, 2021
- CVE-2021-3669621Monitor
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social me
MediumCVSS 5.4No exploitEPSS 1%deskpro · deskproSep 7, 2021
- CVE-2021-3669521Monitor
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the downl
MediumCVSS 5.4No exploitEPSS 1%deskpro · deskproSep 8, 2021
- CVE-2003-087420Monitor
Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized
MediumCVSS 5.0No exploitEPSS 1%deskpro · deskproNov 17, 2003
- CVE-2007-201118Monitor
Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via th
MediumCVSS 4.3Proof of conceptEPSS 2%deskpro · deskproApr 12, 2007
- CVE-2020-1146617Monitor
An issue was discovered in Deskpro before 2019.8.0.
MediumCVSS 4.3No exploitEPSS 1%deskpro · deskproApr 1, 2020
- CVE-2020-1146417Monitor
An issue was discovered in Deskpro before 2019.8.0.
MediumCVSS 4.3No exploitEPSS 1%deskpro · deskproApr 1, 2020
- CVE-2007-101217Monitor
Cross-site scripting (XSS) vulnerability in faq.php in DeskPRO 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the
MediumCVSS 4.3No exploitEPSS 1%deskpro · deskproFeb 21, 2007