uvdesk community-skeleton

5 known vulnerabilities in uvdesk community-skeleton, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-105029 CVSS 5.3 medium UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of…
  • CVE-2025-71421 CVSS 8.6 high UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents…
  • CVE-2025-71420 CVSS 5.3 medium UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated…
  • CVE-2025-71419 CVSS 5.1 medium UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier…
  • CVE-2026-92805 CVSS 9.3 critical UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk…