Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.1
CVE-2026-48209
An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform…
Otrs
after 7.0.49
MEDIUM 6.5
CVE-2026-48208
An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially …
Otrs
2026.4.1+
CRITICAL 9.1
CVE-2026-48188
An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which …
Otrs
2026.4.1+
MEDIUM 5.7
CVE-2026-48187
An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the…
Otrs
2026.4.1+
MEDIUM 5.7
CVE-2026-48189
An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups…
Otrs
2026.4.1+
MEDIUM 5.7
CVE-2026-48210
An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default …
Otrs
Mitigation only
MEDIUM 6.5
CVE-2025-24387
A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive
cookie settings in HTTPS sessions. A req…
Otrs
after 2025.1.2
HIGH 7.5
CVE-2024-23794
An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an age…
Otrs
2024.5.2+
MEDIUM 5.3
CVE-2024-6540
Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS could allow an authorized user t…
Otrs
2024.5.2+
CRITICAL 9.8
CVE-2024-23790
Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes.
T…
Otrs
7.0.49 / 2024.1.1+
HIGH 7.5
CVE-2024-23791
Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issu…
Otrs
7.0.49 / 2024.1.1+
MEDIUM 6.5
CVE-2024-23792
When adding attachments to ticket comments,
another user can add attachments as well impersonating the orginal user. The attack requires a
logged-i…
Otrs
7.0.49 / 2024.1.1+
HIGH 7.5
CVE-2023-6254
A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the serv…
Otrs
after 8.0.37
CRITICAL 9.1
CVE-2023-5422
The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the
SSL_…
Otrs
7.0.47 / 8.0.37+
MEDIUM 5.5
CVE-2023-5421
An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate the CustomerID field to execute…
Otrs
7.0.47 / 8.0.37+
MEDIUM 5.3
CVE-2023-38059
The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to ret…
Otrs
7.0.47 / 8.0.37+
HIGH 8.8
CVE-2023-38060
Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic I…
Otrs
7.0.45 / 8.0.35+
HIGH 7.2
CVE-2023-38056
Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows …
Otrs
7.0.45 / 8.0.35+
MEDIUM 5.4
CVE-2023-38057
An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject …
Survey
7.0.32 / 8.0.13+
HIGH 8.1
CVE-2023-2534
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and…
Otrs
8.0.32+
MEDIUM 6.1
CVE-2018-17883
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to a…
Otrs
6.0.12+
HIGH 7.8
CVE-2023-1250
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Cod…
Otrs
7.0.42 / 8.0.31+
MEDIUM 6.1
CVE-2023-1248
Improper Input Validation vulnerability in OTRS AG OTRS (Ticket Actions modules), OTRS AG ((OTRS)) Community Edition (Ticket Actions modules) allows …
Otrs
7.0.42+
CRITICAL 9.8
CVE-2022-4427
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice
This iss…
Otrs
7.0.40 / 8.0.28+
HIGH 7.5
CVE-2022-3501
Article template contents with sensitive data could be accessed from agents without permissions.
Otrs
8.0.26+
MEDIUM 6.5
CVE-2022-39052
An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the system
Otrs
7.0.39 / 8.0.26+
HIGH 8.8
CVE-2022-39051
Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package
Otrs
7.0.37 / 8.0.25+
MEDIUM 5.3
CVE-2022-32740
A reply to a forwarded email article by a 3rd party could unintensionally expose the email content to the ticket customer under certain circumstances.
Otrs
7.0.35 / 8.0.23+
MEDIUM 5.3
CVE-2022-32741
Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.
Otrs
7.0.35 / 8.0.23+
MEDIUM 5.3
CVE-2022-32739
When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received ICS file contains OTRS relea…
Calendar Resource Planning
7.0.31 / 7.0.35+