Extension WordPress
Vulnérabilités Customer Support Ticket System & Helpdesk
Cette page rassemble les failles publiées pour Customer Support Ticket System & Helpdesk, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Customer Support Ticket System & Helpdesk
8 fiches
WP Ticket <= 6.0.4 – Unauthenticated SQL Injection via WordPress Search 's' Parameter
The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, 6.0.4 The plugin hooks WordPress's `posts_request` filter with `wp_ticket_com_posts_request()`, which calls `emd_author_search_results()` when the…
*-6.0.4
6.0.5
12/06/2026
WP Ticket Customer Service Software & Support Ticket System <= 6.0.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WP Ticket Customer Service Software & Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible…
*-6.0.2
6.0.3
26/09/2025
Multiple Plugins by eMarket Design <= Various Versions – Authenticated (Contributor+) Stored Cross-Site Scripting
Multiple plugins for WordPress by by eMarket Design are vulnerable to Stored Cross-Site Scripting in various versions due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
*-6.0.0
6.0.1
23/09/2025
WP Ticket Customer Service Software & Support Ticket System <= 6.0.2 – Unauthenticated PHP Object Injection
The WP Ticket Customer Service Software & Support Ticket System plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.0.2 via deserialization of untrusted input This makes it possible for unauthenticated attackers…
*-6.0.2
6.0.3
25/08/2025
Multiple Plugins by emarket-design <= Multiple Versions – Unauthenticated Limited Remote Code Execution
Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as…
*-6.0.1
6.0.3
05/08/2025
Customer Service Software & Support Ticket System <= 5.12.0 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Customer Service Software & Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.12.0 due to insufficient input sanitization and output escaping. This makes it…
[*, 5.13)
5.13
22/06/2023
Customer Service Software & Support Ticket System < 5.10.4 – Authenticated (Admin+) Stored Cross-Site Scripting
The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fields before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when…
[*, 5.10.4)
5.10.4
20/09/2021
Zebra_Form PHP library <= 2.9.8 – Reflected Cross-Site Scripting
The Zebra_Form library present in the WP Inimat, Ad Swapper, Drug Search, Teaser Maker, and Customer Service Software & Support Ticket System Plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form' and 'control' parameters in…
*-5.5.1
5.6.0
14/02/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.