Known vulnerabilities in the Supportcandy plugin
12 security advisories have been published for the Supportcandy plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- SupportCandy - Security Vulnerability (CVE-2026-1251) MEDIUM
- SupportCandy - SQL Injection (CVE-2026-0683) MEDIUM
- Supportcandy - Authentication Bypass (CVE-2025-10658) MEDIUM
- Supportcandy - Arbitrary File Upload (CVE-2024-13552) MEDIUM
- Supportcandy - SQL Injection (CVE-2023-2719) HIGH
- Supportcandy - SQL Injection (CVE-2023-2805) HIGH
- Supportcandy - SQL Injection (CVE-2023-1730) CRITICAL
- Supportcandy - Cross-Site Scripting (XSS) (CVE-2021-24879) HIGH
- Supportcandy - Security Vulnerability (CVE-2021-24843) MEDIUM
- Supportcandy - Cross-Site Scripting (XSS) (CVE-2021-24878) MEDIUM
- Supportcandy - Cross-Site Scripting (XSS) (CVE-2021-24880) MEDIUM
- Supportcandy - Cross-Site Request Forgery (CSRF) (CVE-2021-24839) HIGH