Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2026-26895
User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.
Osticket
1.18.3+
HIGH 7.5
CVE-2026-22200EPSS 73%
Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export…
Osticket
1.17.7 / 1.18.3+
MEDIUM 6.5
CVE-2025-26241
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbi…
Osticket
after 1.17.5
MEDIUM 6.1
CVE-2023-46967
Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a craf…
Osticket
1.18.0+
MEDIUM 6.5
CVE-2021-45811
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitr…
Osticket
after 1.15.8
HIGH 7.5
CVE-2023-30082
A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using th…
Osticket
No fix yet
CRITICAL 9.8
CVE-2022-31890
SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the orde…
Audit Log
2022-04-21+
HIGH 8.8
CVE-2022-31888
Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.
Osticket
after 1.16.2
MEDIUM 6.1
CVE-2022-31889
Cross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6…
Audit Log
2022-04-21+
MEDIUM 6.1
CVE-2023-1320
Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.
Osticket
1.16.6+
MEDIUM 5.4
CVE-2023-1315
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.
Osticket
1.16.6+
MEDIUM 5.4
CVE-2023-1316
Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.
Osticket
1.16.6+
MEDIUM 5.4
CVE-2023-1317
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.
Osticket
1.16.6+
MEDIUM 5.4
CVE-2023-1318
Cross-site Scripting (XSS) - Generic in GitHub repository osticket/osticket prior to v1.16.6.
Osticket
1.16.6+
MEDIUM 5.4
CVE-2022-4271
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4.
Osticket
1.16.4+
MEDIUM 5.4
CVE-2022-32074
A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889f…
Osticket
2022-05-19+
CRITICAL 9.8
CVE-2021-42235
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile fu…
Osticket
1.14.8 / 1.15.4+
MEDIUM 6.1
CVE-2020-22608
Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php.
Osticket
1.12.6+
MEDIUM 6.1
CVE-2020-22609
Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.
Osticket
1.12.6+
CRITICAL 9.8
CVE-2020-24881EPSS 73%
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
Osticket
1.14.3+
MEDIUM 6.1
CVE-2020-24917
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.
Osticket
1.14.3+
MEDIUM 5.4
CVE-2020-16193
osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.
Osticket
1.14.3+
MEDIUM 5.4
CVE-2020-14012
scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent.
Osticket
No fix yet
MEDIUM 5.4
CVE-2020-12629
include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.
Osticket
1.14.2+
HIGH 8.8
CVE-2019-14749EPSS 10%
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionali…
Osticket
1.10.7 / 1.12.1+
MEDIUM 6.1
CVE-2019-14750EPSS 11%
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input san…
Osticket
1.10.7 / 1.12.1+
MEDIUM 5.4
CVE-2019-14748
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries.…
Osticket
1.10.7 / 1.12.1+
MEDIUM 6.1
CVE-2019-13397
Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitra…
Osticket
Mitigation only
MEDIUM 6.1
CVE-2019-11537
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent ma…
Osticket
1.12+
HIGH 8.1
CVE-2018-7195
Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging gu…
Osticket
after 1.10.1