Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Zammad HIGH 7.2
CVE-2026-34724

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RC…

Mitigation only
Fix from $1,950 2026-04-08
Zammad MEDIUM 5.7
CVE-2026-34248

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other'…

Mitigation only
Fix from $1,600 2026-04-08
Zammad MEDIUM 6.7
CVE-2024-36078

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server t…

Mitigation only
Fix from $1,600 2024-05-19
Zammad HIGH 7.5
CVE-2023-50455

An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many…

Mitigation only
Fix from $1,950 2023-12-10
Zammad MEDIUM 5.9
CVE-2023-50454

An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper …

Mitigation only
Fix from $1,600 2023-12-10
Zammad MEDIUM 5.3
CVE-2023-50453

An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal con…

Mitigation only
Fix from $1,600 2023-12-10
Zammad MEDIUM 5.3
CVE-2023-50456

An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last n…

Mitigation only
Fix from $1,600 2023-12-10
Zammad CRITICAL 9.8
CVE-2022-48021

A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.

Mitigation only
Fix from $2,300 2023-02-03
Zammad CRITICAL 9.8
CVE-2022-35490

Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a co…

Mitigation only
Fix from $2,300 2022-08-08
Zammad HIGH 7.5
CVE-2022-35487

Zammad 5.2.0 suffers from Incorrect Access Control. Zammad did not correctly perform authorization on certain attachment endpoints. This could be abu…

Mitigation only
Fix from $1,950 2022-08-08
Zammad HIGH 7.5
CVE-2022-35488

In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a know…

Mitigation only
Fix from $1,950 2022-08-08
Zammad MEDIUM 6.5
CVE-2022-35489

In Zammad 5.2.0, customers who have secondary organizations assigned were able to see all organizations of the system rather than only those to which…

Mitigation only
Fix from $1,600 2022-08-08
Zammad HIGH 8.1
CVE-2021-43145

With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.

No fix yet
Fix from $1,950 2022-02-04
Zammad MEDIUM 5.3
CVE-2021-44886

In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as t…

Mitigation only
Fix from $1,600 2022-02-04