Z
ZenDesk
Security Risk Profile
40
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 7 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 11, 2015 to present
7
Total CVEs
3
Critical+High
0
Exploited
2
Unpatched
Threat Assessment
Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
40/100
medium
Severity Distribution
Critical
0High
3Medium
1Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
XSS
2
2
Input Validation
1
Most Affected Products
1. Zendesk Zendesk2
2. Zendesk SweetHawk Survey1
3. Zendesk Samson1
4. Zendesk Enc Datavault1
5. Zendesk Enc Vaultapi1
Recent Vulnerabilities
See more →CVE-2019-25263
CVSS 6.4medium
Zendesk App SweetHawk Survey 1.6 - Persistent Cross-Site Scripting
Feb 3, 2026🔧 No Patch
https://www.theregister.com/2025/11/27/scattered_lapsus_hunters_zendesk/
unknown
Zendesk users targeted as Scattered Lapsus$ Hunters spin up fake support sites
Nov 27, 2025🔧 No Patch
CVE-2024-49193
CVSS 7.5EPSS 0%high
Oct 12, 2024🔧 No Patch
GHSL-2023-136
unknown
Remote Code Execution (RCE) in Samson
Aug 14, 2024🔧 No Patch
CVE-2021-36750
CVSS 8.1high
Dec 22, 2021🔧 No Patch
CVE-2018-20857
CVSS 7.5high
Jul 26, 2019
CVE-2015-6921
CVSS 2.6low
Sep 11, 2015
Monitor ZenDesk in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.