
CVE-2026-23758 GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject maliciou… https://www.cve.org/CVERecord?id=CVE-2026-23758
Post summary
The text announces a stored XSS vulnerability (CVE-2026-23758) in GFI HelpDesk versions before 4.99.9, detailing how authenticated staff can inject malicious content.

