VendorsSolarwindswebhelpdeskall versions
Vulnerabilities

Solarwinds Web Help Desk (WHD)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2021-35254
Authenticated Remote Code Execution in WebHelpDesk 12.7.8
Published 2022-03-25 · Modified
8.8EPSS 0.010
CVE-2019-20002
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.
Published 2020-04-27 · Modified
7.8EPSS 0.013
CVE-2021-35232
Hard credentials discovered in SolarWinds Web Help Desk which allows to execute Arbitrary Hibernate Queries
Published 2021-12-27 · Modified
6.8EPSS 0.003
CVE-2019-16959
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
Published 2020-12-21 · Modified
6.5EPSS 0.017
CVE-2019-16955
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
Published 2020-12-18 · Modified
5.4EPSS 0.017
CVE-2019-16957
SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.
Published 2020-12-18 · Modified
5.4EPSS 0.015