Vulnerability index

Browse CVEs

40 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Request Tracker CRITICAL 9.1
CVE-2026-44231

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an informa…

Fix: 5.0.10 / 6.0.3+
Fix from $2,300 2026-07-20
Request Tracker MEDIUM 6.1
CVE-2026-44230

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not in…

Fix: 5.0.10 / 6.0.3+
Fix from $1,600 2026-07-20
Request Tracker MEDIUM 5.4
CVE-2026-44229

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a…

No fix yet
Fix from $1,600 2026-07-20
Request Tracker MEDIUM 6.1
CVE-2026-44227

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scri…

Fix: 6.0.3+
Fix from $1,600 2026-07-20
Request Tracker MEDIUM 5.4
CVE-2026-44228

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Script…

Fix: 6.0.3+
Fix from $1,600 2026-07-20
Request Tracker MEDIUM 6.1
CVE-2026-6841

Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft…

Fix: 5.0.10 / 6.0.3+
Fix from $1,600 2026-05-21
Request Tracker MEDIUM 6.1
CVE-2025-30087

Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.

Fix: 4.4.8 / 5.0.8+
Fix from $1,600 2025-05-28
Request Tracker MEDIUM 6.1
CVE-2025-31500

Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.

Fix: 5.0.8+
Fix from $1,600 2025-05-28
Request Tracker MEDIUM 6.1
CVE-2025-31501

Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.

Fix: 4.4.8 / 5.0.8+
Fix from $1,600 2025-05-28
Request Tracker HIGH 7.5
CVE-2023-45024

Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.

Fix: 5.0.5+
Fix from $1,950 2023-11-03
Request Tracker HIGH 7.5
CVE-2023-41259

Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email …

Fix: 4.4.7 / 5.0.5+
Fix from $1,950 2023-11-03
Request Tracker HIGH 7.5
CVE-2023-41260

Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.

Fix: 4.4.7 / 5.0.5+
Fix from $1,950 2023-11-03
Request Tracker For Incident Response CRITICAL 9.1
CVE-2022-25800

Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.

Fix: 4.0.3 / 5.0.3+
Fix from $2,300 2022-07-14
Request Tracker For Incident Response CRITICAL 9.1
CVE-2022-25801

Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.

Fix: 4.0.3 / 5.0.3+
Fix from $2,300 2022-07-14
Request Tracker MEDIUM 6.1
CVE-2022-25802

Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.

Fix: 4.4.6 / 5.0.3+
Fix from $1,600 2022-07-14
Request Tracker MEDIUM 6.1
CVE-2022-25803

Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.

Fix: 5.0.3+
Fix from $1,600 2022-07-14
Request Tracker HIGH 8.8
CVE-2017-5943

Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cro…

Mitigation only
Fix from $1,950 2017-07-03
Request Tracker HIGH 8.8
CVE-2017-5944

The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authen…

Mitigation only
Fix from $1,950 2017-07-03
Request Tracker MEDIUM 6.1
CVE-2016-6127

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownl…

Mitigation only
Fix from $1,600 2017-07-03
Request Tracker MEDIUM 5.9
CVE-2017-5361

Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time comparison algorithm for secrets, wh…

Mitigation only
Fix from $1,600 2017-07-03
Request Tracker MEDIUM 5.0
CVE-2013-3737

The MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13, when using the file-based session store (…

Patch available
Fix from $1,600 2014-11-16
Rt MEDIUM 5.0
CVE-2014-1474

Algorithmic complexity vulnerability in Email::Address::List before 0.02, as used in RT 4.2.0 through 4.2.2, allows remote attackers to cause a denia…

Fix: after 0.01
Fix from $1,600 2014-07-15
Rt MEDIUM 6.8
CVE-2013-3370

Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which allows remot…

Patch available
Fix from $1,600 2013-08-23
Rt MEDIUM 6.0
CVE-2013-3369

Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote authenticated users with the permissions to view the administration pa…

Patch available
Fix from $1,600 2013-08-23
Rt MEDIUM 5.0
CVE-2013-3373

CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP hea…

Patch available
Fix from $1,600 2013-08-23
Rt MEDIUM 6.0
CVE-2012-4733

Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote a…

Patch available
Fix from $1,600 2013-08-23
Request Tracker MEDIUM 6.4
CVE-2012-6579

Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encryption or sig…

Patch available
Fix from $1,600 2013-07-24
Request Tracker HIGH 7.5
CVE-2013-3525

SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via th…

Fix: after 4.0.9
Fix from $1,950 2013-05-10
Rt MEDIUM 6.8
CVE-2012-4732

Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versions before …

Patch available
Fix from $1,600 2012-11-11
Rt MEDIUM 5.0
CVE-2012-4734

Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warn…

Mitigation only
Fix from $1,600 2012-11-11