Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-48209 An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform… Otrs after 7.0.49 Fix from $1,9502026-06-01 MEDIUM 6.5 CVE-2026-48208 An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially … Otrs 2026.4.1+ Fix from $1,6002026-06-01 CRITICAL 9.1 CVE-2026-48188 An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which … Otrs 2026.4.1+ Fix from $2,3002026-06-01 MEDIUM 5.7 CVE-2026-48187 An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the… Otrs 2026.4.1+ Fix from $1,6002026-06-01 MEDIUM 5.7 CVE-2026-48189 An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups… Otrs 2026.4.1+ Fix from $1,6002026-06-01 MEDIUM 5.7 CVE-2026-48210 An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default … Otrs Mitigation only Fix from $1,6002026-05-31 MEDIUM 6.5 CVE-2025-24387 A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A req… Otrs after 2025.1.2 Fix from $1,6002025-03-10 HIGH 7.5 CVE-2024-23794 An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an age… Otrs 2024.5.2+ Fix from $1,9502024-07-15 MEDIUM 5.3 CVE-2024-6540 Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS could allow an authorized user t… Otrs 2024.5.2+ Fix from $1,6002024-07-15 CRITICAL 9.8 CVE-2024-23790 Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. T… Otrs 7.0.49 / 2024.1.1+ Fix from $2,3002024-01-29 HIGH 7.5 CVE-2024-23791 Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issu… Otrs 7.0.49 / 2024.1.1+ Fix from $1,9502024-01-29 MEDIUM 6.5 CVE-2024-23792 When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-i… Otrs 7.0.49 / 2024.1.1+ Fix from $1,6002024-01-29 HIGH 7.5 CVE-2023-6254 A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the serv… Otrs after 8.0.37 Fix from $1,9502023-11-27 CRITICAL 9.1 CVE-2023-5422 The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_… Otrs 7.0.47 / 8.0.37+ Fix from $2,3002023-10-16 MEDIUM 5.5 CVE-2023-5421 An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate the CustomerID field to execute… Otrs 7.0.47 / 8.0.37+ Fix from $1,6002023-10-16 MEDIUM 5.3 CVE-2023-38059 The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to ret… Otrs 7.0.47 / 8.0.37+ Fix from $1,6002023-10-16 HIGH 8.8 CVE-2023-38060 Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic I… Otrs 7.0.45 / 8.0.35+ Fix from $1,9502023-07-24 HIGH 7.2 CVE-2023-38056 Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows … Otrs 7.0.45 / 8.0.35+ Fix from $1,9502023-07-24 MEDIUM 5.4 CVE-2023-38057 An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject … Survey 7.0.32 / 8.0.13+ Fix from $1,6002023-07-24 HIGH 8.1 CVE-2023-2534 Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and… Otrs 8.0.32+ Fix from $1,9502023-05-08 MEDIUM 6.1 CVE-2018-17883 An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to a… Otrs 6.0.12+ Fix from $1,6002023-04-16 HIGH 7.8 CVE-2023-1250 Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Cod… Otrs 7.0.42 / 8.0.31+ Fix from $1,9502023-03-20 MEDIUM 6.1 CVE-2023-1248 Improper Input Validation vulnerability in OTRS AG OTRS (Ticket Actions modules), OTRS AG ((OTRS)) Community Edition (Ticket Actions modules) allows … Otrs 7.0.42+ Fix from $1,6002023-03-20 CRITICAL 9.8 CVE-2022-4427 Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This iss… Otrs 7.0.40 / 8.0.28+ Fix from $2,3002022-12-19 HIGH 7.5 CVE-2022-3501 Article template contents with sensitive data could be accessed from agents without permissions. Otrs 8.0.26+ Fix from $1,9502022-10-17 MEDIUM 6.5 CVE-2022-39052 An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the system Otrs 7.0.39 / 8.0.26+ Fix from $1,6002022-10-17 HIGH 8.8 CVE-2022-39051 Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package Otrs 7.0.37 / 8.0.25+ Fix from $1,9502022-09-05 MEDIUM 5.3 CVE-2022-32740 A reply to a forwarded email article by a 3rd party could unintensionally expose the email content to the ticket customer under certain circumstances. Otrs 7.0.35 / 8.0.23+ Fix from $1,6002022-06-13 MEDIUM 5.3 CVE-2022-32741 Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time. Otrs 7.0.35 / 8.0.23+ Fix from $1,6002022-06-13 MEDIUM 5.3 CVE-2022-32739 When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received ICS file contains OTRS relea… Calendar Resource Planning 7.0.31 / 7.0.35+ Fix from $1,6002022-06-13