Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Otrs HIGH 7.1
CVE-2026-48209

An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform…

Fix: after 7.0.49
Fix from $1,950 2026-06-01
Otrs MEDIUM 6.5
CVE-2026-48208

An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially …

Fix: 2026.4.1+
Fix from $1,600 2026-06-01
Otrs CRITICAL 9.1
CVE-2026-48188

An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which …

Fix: 2026.4.1+
Fix from $2,300 2026-06-01
Otrs MEDIUM 5.7
CVE-2026-48187

An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the…

Fix: 2026.4.1+
Fix from $1,600 2026-06-01
Otrs MEDIUM 5.7
CVE-2026-48189

An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups…

Fix: 2026.4.1+
Fix from $1,600 2026-06-01
Otrs MEDIUM 5.7
CVE-2026-48210

An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default …

Mitigation only
Fix from $1,600 2026-05-31
Otrs MEDIUM 6.5
CVE-2025-24387

A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A req…

Fix: after 2025.1.2
Fix from $1,600 2025-03-10
Otrs HIGH 7.5
CVE-2024-23794

An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an age…

Fix: 2024.5.2+
Fix from $1,950 2024-07-15
Otrs MEDIUM 5.3
CVE-2024-6540

Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS could allow an authorized user t…

Fix: 2024.5.2+
Fix from $1,600 2024-07-15
Otrs CRITICAL 9.8
CVE-2024-23790

Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. T…

Fix: 7.0.49 / 2024.1.1+
Fix from $2,300 2024-01-29
Otrs HIGH 7.5
CVE-2024-23791

Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issu…

Fix: 7.0.49 / 2024.1.1+
Fix from $1,950 2024-01-29
Otrs MEDIUM 6.5
CVE-2024-23792

When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-i…

Fix: 7.0.49 / 2024.1.1+
Fix from $1,600 2024-01-29
Otrs HIGH 7.5
CVE-2023-6254

A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the serv…

Fix: after 8.0.37
Fix from $1,950 2023-11-27
Otrs CRITICAL 9.1
CVE-2023-5422

The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_…

Fix: 7.0.47 / 8.0.37+
Fix from $2,300 2023-10-16
Otrs MEDIUM 5.5
CVE-2023-5421

An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate the CustomerID field to execute…

Fix: 7.0.47 / 8.0.37+
Fix from $1,600 2023-10-16
Otrs MEDIUM 5.3
CVE-2023-38059

The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to ret…

Fix: 7.0.47 / 8.0.37+
Fix from $1,600 2023-10-16
Otrs HIGH 8.8
CVE-2023-38060

Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic I…

Fix: 7.0.45 / 8.0.35+
Fix from $1,950 2023-07-24
Otrs HIGH 7.2
CVE-2023-38056

Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows …

Fix: 7.0.45 / 8.0.35+
Fix from $1,950 2023-07-24
Survey MEDIUM 5.4
CVE-2023-38057

An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject …

Fix: 7.0.32 / 8.0.13+
Fix from $1,600 2023-07-24
Otrs HIGH 8.1
CVE-2023-2534

Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and…

Fix: 8.0.32+
Fix from $1,950 2023-05-08
Otrs MEDIUM 6.1
CVE-2018-17883

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to a…

Fix: 6.0.12+
Fix from $1,600 2023-04-16
Otrs HIGH 7.8
CVE-2023-1250

Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Cod…

Fix: 7.0.42 / 8.0.31+
Fix from $1,950 2023-03-20
Otrs MEDIUM 6.1
CVE-2023-1248

Improper Input Validation vulnerability in OTRS AG OTRS (Ticket Actions modules), OTRS AG ((OTRS)) Community Edition (Ticket Actions modules) allows …

Fix: 7.0.42+
Fix from $1,600 2023-03-20
Otrs CRITICAL 9.8
CVE-2022-4427

Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This iss…

Fix: 7.0.40 / 8.0.28+
Fix from $2,300 2022-12-19
Otrs HIGH 7.5
CVE-2022-3501

Article template contents with sensitive data could be accessed from agents without permissions.

Fix: 8.0.26+
Fix from $1,950 2022-10-17
Otrs MEDIUM 6.5
CVE-2022-39052

An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the system

Fix: 7.0.39 / 8.0.26+
Fix from $1,600 2022-10-17
Otrs HIGH 8.8
CVE-2022-39051

Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package

Fix: 7.0.37 / 8.0.25+
Fix from $1,950 2022-09-05
Otrs MEDIUM 5.3
CVE-2022-32740

A reply to a forwarded email article by a 3rd party could unintensionally expose the email content to the ticket customer under certain circumstances.

Fix: 7.0.35 / 8.0.23+
Fix from $1,600 2022-06-13
Otrs MEDIUM 5.3
CVE-2022-32741

Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.

Fix: 7.0.35 / 8.0.23+
Fix from $1,600 2022-06-13
Calendar Resource Planning MEDIUM 5.3
CVE-2022-32739

When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received ICS file contains OTRS relea…

Fix: 7.0.31 / 7.0.35+
Fix from $1,600 2022-06-13