
CVE-2026-23752 GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated adm… https://www.cve.org/CVERecord?id=CVE-2026-23752
Post summary
A stored XSS vulnerability in GFI HelpDesk versions before 4.99.9 allows authenticated administrators to inject scripts during template group creation or editing, as outlined in CVE‑2026‑23752.

