CVE-2019-16954: SolarWinds Web Help Desk

Medium severity, CVSS 5.4. EPSS: 1.3% chance of exploitation in the next 30 days.

SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.

Affected products

Published 2021-01-06. Last modified 2026-06-17.