WebHelpDesk
by SolarWinds
CVEs (27)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16960 | Med | 0.35 | 5.4 | 0.01 | Jan 4, 2021 | SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field. | ||
| CVE-2019-16956 | Med | 0.35 | 5.4 | 0.02 | Jan 4, 2021 | SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket. | ||
| CVE-2019-16957 | Med | 0.35 | 5.4 | 0.01 | Dec 18, 2020 | SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account. | ||
| CVE-2019-16955 | Med | 0.35 | 5.4 | 0.02 | Dec 18, 2020 | SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request. | ||
| CVE-2019-16958 | Med | 0.35 | 5.4 | 0.01 | Dec 1, 2020 | Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name. | ||
| CVE-2025-26400 | Med | 0.34 | 5.3 | 0.00 | Jul 29, 2025 | SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files. | ||
| CVE-2024-45709 | Med | 0.34 | 5.3 | 0.01 | Dec 10, 2024 | SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and configured to use non-default development/test mode making exposure to the vulnerability very limited. |
- risk 0.35cvss 5.4epss 0.01
SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.
- risk 0.35cvss 5.4epss 0.02
SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.
- risk 0.35cvss 5.4epss 0.01
SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.
- risk 0.35cvss 5.4epss 0.02
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
- risk 0.35cvss 5.4epss 0.01
Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.
- risk 0.34cvss 5.3epss 0.00
SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.
- risk 0.34cvss 5.3epss 0.01
SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and configured to use non-default development/test mode making exposure to the vulnerability very limited.
Page 2 of 2