📦 Freescout

by Freescout

🔍 What is Freescout?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-28289

CRITICAL CVSS 10.0 Mar 3, 2026

This CVE describes a patch bypass vulnerability in FreeScout help desk software that allows authenticated users with file upload permissions to achieve Remote Code Execution (RCE) by uploading malicio...

CVE-2026-27637

CRITICAL CVSS 9.8 Feb 25, 2026

FreeScout's authentication system uses a predictable, static token that never expires. If an attacker obtains the Laravel APP_KEY (commonly exposed), they can generate valid authentication tokens for ...

CVE-2025-48481

CRITICAL CVSS 9.8 May 30, 2025

This vulnerability allows attackers with unactivated email invitations to self-activate blocked or deleted accounts in FreeScout help desk software. Attackers can gain unauthorized access to accounts ...

CVE-2025-48471

CRITICAL CVSS 9.8 May 29, 2025

FreeScout versions before 1.8.179 have an unrestricted file upload vulnerability that allows attackers to upload malicious PHP files (.phtml, .phar extensions) to the web server. When Apache is used, ...

CVE-2024-29185

CRITICAL CVSS 9.0 Mar 22, 2024

FreeScout versions before 1.8.128 contain an OS command injection vulnerability in the tools.php file that allows authenticated attackers with the App_Key to execute arbitrary commands on the server. ...

CVE-2026-27636

HIGH CVSS 8.8 Feb 25, 2026

This vulnerability allows authenticated users to upload .htaccess or .user.ini files to FreeScout help desk systems, enabling remote code execution on Apache servers with AllowOverride All configurati...

CVE-2025-58163

HIGH CVSS 8.8 Sep 3, 2025

CVE-2025-58163 is a remote code execution vulnerability in FreeScout help desk software where authenticated attackers with knowledge of the application's APP_KEY can execute arbitrary commands on the ...

CVE-2025-54366

HIGH CVSS 8.8 Jul 26, 2025

CVE-2025-54366 is a critical deserialization vulnerability in FreeScout help desk software that allows authenticated attackers with knowledge of the APP_KEY to achieve remote code execution. The vulne...

CVE-2025-48476

HIGH CVSS 8.8 May 30, 2025

FreeScout versions before 1.8.180 have a mass-assignment vulnerability in user record editing that allows authenticated users with edit permissions to change other users' passwords without proper vali...

CVE-2025-48475

HIGH CVSS 8.1 May 29, 2025

CVE-2025-48475 is an authorization bypass vulnerability in FreeScout help desk software where authenticated users without mailbox or conversation access can view and edit all client data. This affects...

CVE-2025-48474

HIGH CVSS 8.1 May 29, 2025

FreeScout help desk software versions before 1.8.180 contain an access control vulnerability where users with 'show_only_assigned_conversations' enabled can assign themselves to arbitrary conversation...

CVE-2025-48390

HIGH CVSS 7.2 May 29, 2025

FreeScout versions before 1.8.178 contain a code injection vulnerability in the php_path parameter. Administrators can exploit this to execute arbitrary system commands via backticks, potentially lead...

CVE-2024-34697

HIGH CVSS 7.6 May 14, 2024

A stored HTML injection vulnerability in FreeScout's email reception module allows unauthenticated attackers to inject malicious HTML content into emails processed by the application. This affects all...

CVE-2024-29184

HIGH CVSS 8.0 Mar 22, 2024

A stored cross-site scripting (XSS) vulnerability in FreeScout's signature input field allows support agents to inject malicious JavaScript that executes when administrators view the signature. This b...

CVE-2024-28186

HIGH CVSS 7.1 Mar 12, 2024

This vulnerability in FreeScout exposes SMTP server credentials to authenticated users through stack traces stored in the database and accessible via a specific endpoint. Attackers can steal these cre...

CVE-2025-48880

MEDIUM CVSS 6.6 May 30, 2025

FreeScout versions before 1.8.181 contain a race condition vulnerability when administrators delete users. This could allow attackers to cause unexpected behavior or potentially escalate privileges. O...

CVE-2025-48486

MEDIUM CVSS 5.4 May 30, 2025

FreeScout versions before 1.8.180 contain a cross-site scripting (XSS) vulnerability in the Session::flash and __ functions due to insufficient input validation and sanitization. This allows attackers...

CVE-2025-48488

MEDIUM CVSS 5.4 May 30, 2025

CVE-2025-48488 is a Cross-Site Scripting vulnerability in FreeScout help desk software where deleting the .htaccess file allows attackers to upload malicious HTML files containing JavaScript. This aff...

CVE-2025-48483

MEDIUM CVSS 5.4 May 30, 2025

FreeScout versions before 1.8.180 are vulnerable to stored XSS attacks through mail signature sanitization. Attackers can inject malicious HTML/JavaScript that executes when users view emails, potenti...

CVE-2025-48478

MEDIUM CVSS 4.9 May 30, 2025

FreeScout versions before 1.8.180 have a mass assignment vulnerability during user creation that allows attackers to manipulate all fields in the User object. This affects all FreeScout instances runn...

CVE-2025-48473

MEDIUM CVSS 4.3 May 29, 2025

This vulnerability in FreeScout allows authenticated users to view messages from conversations they shouldn't have access to when creating new conversations from existing messages. It affects all Free...

CVE-2025-48388

MEDIUM CVSS 6.5 May 29, 2025

FreeScout help desk software prior to version 1.8.178 has an input validation vulnerability where special characters like carriage returns, newlines, and tabs can be passed to string formatting functi...