Known Vulnerabilities for products from Kayako

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Kayako".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2022-35913 json Samourai Wallet Stonewallx2 0.99.98e allows a denial of service via a P2P coinjoin. The attacker and victim must follow each ... 4.3 - MEDIUM 2022-09-06 2022-09-16
CVE-2012-4872 json Cross-site scripting (XSS) vulnerability in Tickets/Submit in Kayako Fusion before 4.40.985 allows remote attackers to inject... Not Provided 2012-09-06 2026-04-29
CVE-2012-3233 json Cross-site scripting (XSS) vulnerability in __swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in Kayako Fusi... Not Provided 2012-09-15 2026-04-29
CVE-2010-2912 json SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands... Not Provided 2010-07-28 2026-04-29
CVE-2010-2911 json SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands... Not Provided 2010-07-28 2026-04-29
CVE-2010-0460 json Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php in Kayako SupportSuite 3.60.04 and earlier allow remot... Not Provided 2010-01-28 2026-04-29
CVE-2009-3567 json Cross-site scripting (XSS) vulnerability in modules/tickets/functions_ticketsui.php in Kayako SupportSuite and eSupport 3.60.... Not Provided 2009-10-06 2026-04-23
CVE-2009-3427 json Cross-site scripting (XSS) vulnerability in Kayako SupportSuite 3.50.06 allows remote attackers to inject arbitrary web scrip... Not Provided 2009-09-25 2026-04-23
CVE-2008-4761 json Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.20.2 ... Not Provided 2008-10-28 2026-04-23
CVE-2008-3701 json SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and earlier allows remote authenticated users t... Not Provided 2008-08-15 2026-04-23
CVE-2008-3700 json Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inje... Not Provided 2008-08-15 2026-04-23
CVE-2008-0395 json Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml... Not Provided 2008-01-23 2026-04-23
CVE-2007-2562 json Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 3.00.90 allows remote attackers to inject arbitrary ... Not Provided 2007-05-09 2026-04-23
CVE-2007-1145 json Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attack... Not Provided 2007-03-02 2026-04-23
CVE-2006-5825 json Cross-site scripting (XSS) vulnerability in index.php in Kayako SupportSuite 3.00.32 allows remote attackers to inject arbitr... Not Provided 2006-11-10 2026-04-23
CVE-2006-4011 json PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and earlier, when register_g... 2.6 - LOW 2006-08-07 2017-10-19
CVE-2005-4638 json index.php in Kayako SupportSuite 3.00.26 and earlier allow remote attackers to obtain the full path via (1) _a and (2) newsid... Not Provided 2005-12-31 2025-04-03
CVE-2005-4637 json Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kayako SupportSuite 3.00.26 and earlier allow remote atta... Not Provided 2005-12-31 2025-04-03
CVE-2005-2463 json Kayako liveResponse 2.x allows remote attackers to obtain sensitive information via a direct request to addressbook.php and o... Not Provided 2005-12-31 2025-04-03
CVE-2005-2462 json Kayako liveResponse 2.x, when logging in a user, records the password in plaintext in the URL, which allows local users and p... Not Provided 2005-12-31 2025-04-03

Known software with vulnerabilities from Kayako

Type Vendor Product Version
ApplicationKayakoFusion4.40.1148

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report