Known Vulnerabilities for products from Intercom
Listed below are 8 of the newest known vulnerabilities associated with the vendor "Intercom".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-31280 json | Not Provided | 2026-04-13 | 2026-05-10 | |
| CVE-2025-4994 json | Not Provided | 2026-06-22 | 2026-07-07 | |
| CVE-2019-14365 json | The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of in... | 7.5 - HIGH | 2019-11-12 | 2019-11-14 |
| CVE-2017-10819 json | MaLion for Mac 4.3.0 to 5.2.1 does not properly validate certificates, which may allow an attacker to eavesdrop on an encrypt... | Not Provided | 2017-08-04 | 2025-04-20 |
| CVE-2017-10818 json | MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter th... | Not Provided | 2017-08-04 | 2025-04-20 |
| CVE-2017-10817 json | MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Service... | Not Provided | 2017-08-04 | 2025-04-20 |
| CVE-2017-10816 json | SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL... | Not Provided | 2017-08-04 | 2025-04-20 |
| CVE-2017-10815 json | MaLion for Windows 5.2.1 and earlier (only when "Remote Control" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when "... | Not Provided | 2017-08-04 | 2025-04-20 |
| CVE-2014-3881 json | Cross-site request forgery (CSRF) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to hijac... | Not Provided | 2014-06-28 | 2026-05-06 |
| CVE-2014-2006 json | Cross-site scripting (XSS) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to inject arbit... | Not Provided | 2014-06-28 | 2026-05-06 |
Known software with vulnerabilities from Intercom
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Intercom | Intercom | - |
| Application | Intercom | Malion | 5.2.1 |
| Application | Intercom | Web Kyukincho | 3.0 |