CVE Feed

    Dashboard / CVE / CVE-2025-68927

    CVE-2025-68927

    Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML injection in the contact notes feature. When adding notes via POST /api/v1/contacts/{id}/notes, the backend automatically wraps user input in <p> tags. However, by intercepting the request and removing the <p> tag, an attacker can inject arbitrary HTML elements such as forms and images, which are then stored and rendered without proper sanitization. This can lead to phishing, CSRF-style forced actions, and UI redress attacks. This issue has been patched in version 0.8.6-beta.

    Published:Dec 27, 2025
    Last Modified:Jan 2, 2026
    EPS:Dec 27, 2025
    EPSS Score:0.00062
    CVSS Score:6.1

    Affected Products

    Vendor
    Abhinavxd
    Product
    Libredesk
    Vendor
    Libredesk
    Product
    Libredesk

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High