Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zammad HIGH 7.5
CVE-2026-34723

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote attackers were able to access th…

Fix: 6.5.4+
Fix from $1,950 2026-04-08
Zammad HIGH 7.2
CVE-2026-34724

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RC…

Mitigation only
Fix from $1,950 2026-04-08
Zammad MEDIUM 6.5
CVE-2026-34721

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints for Microsoft, Google, and…

Fix: 6.5.4+
Fix from $1,600 2026-04-08
Zammad MEDIUM 6.1
CVE-2026-34718

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for ticket articles was missing prop…

Fix: 6.5.4+
Fix from $1,600 2026-04-08
Zammad MEDIUM 5.7
CVE-2026-34248

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other'…

Mitigation only
Fix from $1,600 2026-04-08
Zammad HIGH 8.8
CVE-2025-32359

In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, …

Fix: 6.4.2+
Fix from $1,950 2025-04-05
Zammad HIGH 8.1
CVE-2025-32360

In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged i…

Fix: 6.4.2+
Fix from $1,950 2025-04-05
Zammad MEDIUM 6.7
CVE-2024-36078

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server t…

Mitigation only
Fix from $1,600 2024-05-19
Zammad CRITICAL 9.1
CVE-2024-33668

An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker c…

Fix: 6.3.0+
Fix from $2,300 2024-04-26
Zammad HIGH 8.6
CVE-2024-33666

An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via…

Fix: 6.3.0+
Fix from $1,950 2024-04-26
Zammad MEDIUM 6.5
CVE-2024-33667

An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack by calling an endpoint that ac…

Fix: 6.3.0+
Fix from $1,600 2024-04-26
Zammad HIGH 7.5
CVE-2023-50455

An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many…

Mitigation only
Fix from $1,950 2023-12-10
Zammad MEDIUM 5.9
CVE-2023-50454

An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper …

Mitigation only
Fix from $1,600 2023-12-10
Zammad MEDIUM 5.3
CVE-2023-50453

An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal con…

Mitigation only
Fix from $1,600 2023-12-10
Zammad MEDIUM 5.3
CVE-2023-50456

An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last n…

Mitigation only
Fix from $1,600 2023-12-10
Zammad MEDIUM 6.5
CVE-2023-31597

An issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address and manipulate the data of the generated user. At…

Fix: 5.4.1+
Fix from $1,600 2023-05-18
Zammad MEDIUM 6.5
CVE-2023-29867

Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information about linked accounts of users…

Fix: 5.4.0+
Fix from $1,600 2023-05-02
Zammad MEDIUM 6.5
CVE-2023-29868

Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauth…

Fix: 5.4.0+
Fix from $1,600 2023-05-02
Zammad CRITICAL 9.8
CVE-2022-48021

A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.

Mitigation only
Fix from $2,300 2023-02-03
Zammad MEDIUM 6.5
CVE-2022-40816

Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that customer users are not able to see…

Fix: 5.2.2+
Fix from $1,600 2022-09-27
Zammad CRITICAL 9.8
CVE-2022-35490

Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a co…

Mitigation only
Fix from $2,300 2022-08-08
Zammad HIGH 7.5
CVE-2022-35487

Zammad 5.2.0 suffers from Incorrect Access Control. Zammad did not correctly perform authorization on certain attachment endpoints. This could be abu…

Mitigation only
Fix from $1,950 2022-08-08
Zammad HIGH 7.5
CVE-2022-35488

In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a know…

Mitigation only
Fix from $1,950 2022-08-08
Zammad MEDIUM 6.5
CVE-2022-35489

In Zammad 5.2.0, customers who have secondary organizations assigned were able to see all organizations of the system rather than only those to which…

Mitigation only
Fix from $1,600 2022-08-08
Zammad CRITICAL 9.1
CVE-2022-27332

An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow…

Fix: 5.1.0+
Fix from $2,300 2022-04-27
Zammad HIGH 7.5
CVE-2022-29700

A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) …

Patch available
Fix from $1,950 2022-04-27
Zammad HIGH 7.5
CVE-2022-29701

A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for a legiti…

Patch available
Fix from $1,950 2022-04-27
Zammad HIGH 8.1
CVE-2021-43145

With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.

No fix yet
Fix from $1,950 2022-02-04
Zammad MEDIUM 5.3
CVE-2021-44886

In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as t…

Mitigation only
Fix from $1,600 2022-02-04
Zammad MEDIUM 5.3
CVE-2021-42137

An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of ticke…

Fix: 5.0.1+
Fix from $1,600 2021-10-11