
CVE-2026-23756 GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Cont… https://www.cve.org/CVERecord?id=CVE-2026-23756
Post summary
The post announces the discovery of a stored XSS vulnerability in GFI HelpDesk versions prior to 4.99.9, detailing the affected parameter and module without providing any exploit or mitigation information.

