
CVE-2026-23757 GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly to SWIFT_Report::C… https://www.cve.org/CVERecord?id=CVE-2026-23757
Post summary
The text is a straightforward disclosure of a stored XSS vulnerability in GFI HelpDesk prior to version 4.99.10, providing technical details but no evidence of exploitation, PoC, or patch information.

