Known Vulnerabilities for Uvdesk by Webkul
Listed below are 2 of the newest known vulnerabilities associated with "Uvdesk" by "Webkul".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-105029 json | UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket acti... | Not Provided | 2026-10-03 | 2026-10-06 |
| CVE-2026-92805 json | UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in Configure... | Not Provided | 2026-09-16 | 2026-09-19 |
| CVE-2025-71421 json | UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that all... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2025-71420 json | UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows aut... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2025-71419 json | UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration iden... | Not Provided | 2026-09-21 | 2026-09-24 |
| CVE-2023-39147 json | An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted ima... | 7.8 - HIGH | 2023-08-01 | 2023-08-04 |
| CVE-2023-37636 json | A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary w... | 5.4 - MEDIUM | 2023-10-23 | 2023-10-30 |