GestSup

4 known vulnerabilities in GestSup, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-102374 CVSS 5.3 medium GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes…
  • CVE-2026-102373 CVSS 7.1 high GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php…
  • CVE-2026-102372 CVSS 5.3 medium GestSup versions before 3.2.61 fail to properly sanitize HTML email bodies in the IMAP LOGIN connector, allowing unauthenticated attackers…
  • CVE-2026-100389 CVSS 9.2 critical GestSup versions before 3.2.62 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails…