VYPR

WebHelpDesk

by SolarWinds

CVEs (27)

  • CVE-2019-16960MedJan 4, 2021
    risk 0.35cvss 5.4epss 0.01

    SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.

  • CVE-2019-16956MedJan 4, 2021
    risk 0.35cvss 5.4epss 0.02

    SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.

  • CVE-2019-16957MedDec 18, 2020
    risk 0.35cvss 5.4epss 0.01

    SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.

  • CVE-2019-16955MedDec 18, 2020
    risk 0.35cvss 5.4epss 0.02

    SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.

  • CVE-2019-16958MedDec 1, 2020
    risk 0.35cvss 5.4epss 0.01

    Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.

  • CVE-2025-26400MedJul 29, 2025
    risk 0.34cvss 5.3epss 0.00

    SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.

  • CVE-2024-45709MedDec 10, 2024
    risk 0.34cvss 5.3epss 0.01

    SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and configured to use non-default development/test mode making exposure to the vulnerability very limited.

Page 2 of 2