Known Vulnerabilities for products from Kayako
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Kayako".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-35913 json | Samourai Wallet Stonewallx2 0.99.98e allows a denial of service via a P2P coinjoin. The attacker and victim must follow each ... | 4.3 - MEDIUM | 2022-09-06 | 2022-09-16 |
| CVE-2012-4872 json | Cross-site scripting (XSS) vulnerability in Tickets/Submit in Kayako Fusion before 4.40.985 allows remote attackers to inject... | Not Provided | 2012-09-06 | 2026-04-29 |
| CVE-2012-3233 json | Cross-site scripting (XSS) vulnerability in __swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in Kayako Fusi... | Not Provided | 2012-09-15 | 2026-04-29 |
| CVE-2010-2912 json | SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands... | Not Provided | 2010-07-28 | 2026-04-29 |
| CVE-2010-2911 json | SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands... | Not Provided | 2010-07-28 | 2026-04-29 |
| CVE-2010-0460 json | Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php in Kayako SupportSuite 3.60.04 and earlier allow remot... | Not Provided | 2010-01-28 | 2026-04-29 |
| CVE-2009-3567 json | Cross-site scripting (XSS) vulnerability in modules/tickets/functions_ticketsui.php in Kayako SupportSuite and eSupport 3.60.... | Not Provided | 2009-10-06 | 2026-04-23 |
| CVE-2009-3427 json | Cross-site scripting (XSS) vulnerability in Kayako SupportSuite 3.50.06 allows remote attackers to inject arbitrary web scrip... | Not Provided | 2009-09-25 | 2026-04-23 |
| CVE-2008-4761 json | Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.20.2 ... | Not Provided | 2008-10-28 | 2026-04-23 |
| CVE-2008-3701 json | SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and earlier allows remote authenticated users t... | Not Provided | 2008-08-15 | 2026-04-23 |
| CVE-2008-3700 json | Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inje... | Not Provided | 2008-08-15 | 2026-04-23 |
| CVE-2008-0395 json | Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml... | Not Provided | 2008-01-23 | 2026-04-23 |
| CVE-2007-2562 json | Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 3.00.90 allows remote attackers to inject arbitrary ... | Not Provided | 2007-05-09 | 2026-04-23 |
| CVE-2007-1145 json | Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attack... | Not Provided | 2007-03-02 | 2026-04-23 |
| CVE-2006-5825 json | Cross-site scripting (XSS) vulnerability in index.php in Kayako SupportSuite 3.00.32 allows remote attackers to inject arbitr... | Not Provided | 2006-11-10 | 2026-04-23 |
| CVE-2006-4011 json | PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and earlier, when register_g... | 2.6 - LOW | 2006-08-07 | 2017-10-19 |
| CVE-2005-4638 json | index.php in Kayako SupportSuite 3.00.26 and earlier allow remote attackers to obtain the full path via (1) _a and (2) newsid... | Not Provided | 2005-12-31 | 2025-04-03 |
| CVE-2005-4637 json | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kayako SupportSuite 3.00.26 and earlier allow remote atta... | Not Provided | 2005-12-31 | 2025-04-03 |
| CVE-2005-2463 json | Kayako liveResponse 2.x allows remote attackers to obtain sensitive information via a direct request to addressbook.php and o... | Not Provided | 2005-12-31 | 2025-04-03 |
| CVE-2005-2462 json | Kayako liveResponse 2.x, when logging in a user, records the password in plaintext in the URL, which allows local users and p... | Not Provided | 2005-12-31 | 2025-04-03 |
Known software with vulnerabilities from Kayako
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Kayako | Fusion | 4.40.1148 |