Medium 5.4
2026-01-31< 3.4.5
SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) Insecure Direct Object Reference
Minimum safe version
3.4.5
Update to 3.4.5 or later to address 17 fixable vulnerabilities
SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) Insecure Direct Object Reference
SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) SQL Injection via Number Field Filter
CVE-2026-25321
CVE-2025-67598
CVE-2025-10658
CVE-2024-13552
CVE-2024-27991
SupportCandy <= 3.1.3 - Sensitive Data Exposure
CVE-2023-2719
CVE-2023-2805
CVE-2023-1730
CVE-2019-11223
CVE-2021-24880
CVE-2021-24879
CVE-2021-24878
CVE-2021-24843
CVE-2021-24839