GestSup
4 known vulnerabilities in GestSup, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-102374 CVSS 5.3 medium GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes…
- CVE-2026-102373 CVSS 7.1 high GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php…
- CVE-2026-102372 CVSS 5.3 medium GestSup versions before 3.2.61 fail to properly sanitize HTML email bodies in the IMAP LOGIN connector, allowing unauthenticated attackers…
- CVE-2026-100389 CVSS 9.2 critical GestSup versions before 3.2.62 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails…