Vulnerability index

Browse CVEs

39 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Osticket MEDIUM 5.3
CVE-2026-26895

User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.

Fix: 1.18.3+
Fix from $1,600 2026-04-02
Osticket HIGH 7.5
CVE-2026-22200EPSS 73%

Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export…

Fix: 1.17.7 / 1.18.3+
Fix from $1,950 2026-01-12
Osticket MEDIUM 6.5
CVE-2025-26241

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbi…

Fix: after 1.17.5
Fix from $1,600 2025-05-05
Osticket MEDIUM 6.1
CVE-2023-46967

Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a craf…

Fix: 1.18.0+
Fix from $1,600 2024-02-20
Osticket MEDIUM 6.5
CVE-2021-45811

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitr…

Fix: after 1.15.8
Fix from $1,600 2023-09-08
Osticket HIGH 7.5
CVE-2023-30082

A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using th…

No fix yet
Fix from $1,950 2023-06-14
Audit Log CRITICAL 9.8
CVE-2022-31890

SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the orde…

Fix: 2022-04-21+
Fix from $2,300 2023-04-05
Osticket HIGH 8.8
CVE-2022-31888

Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.

Fix: after 1.16.2
Fix from $1,950 2023-04-05
Audit Log MEDIUM 6.1
CVE-2022-31889

Cross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6…

Fix: 2022-04-21+
Fix from $1,600 2023-04-05
Osticket MEDIUM 6.1
CVE-2023-1320

Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.

Fix: 1.16.6+
Fix from $1,600 2023-03-10
Osticket MEDIUM 5.4
CVE-2023-1315

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

Fix: 1.16.6+
Fix from $1,600 2023-03-10
Osticket MEDIUM 5.4
CVE-2023-1316

Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.

Fix: 1.16.6+
Fix from $1,600 2023-03-10
Osticket MEDIUM 5.4
CVE-2023-1317

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

Fix: 1.16.6+
Fix from $1,600 2023-03-10
Osticket MEDIUM 5.4
CVE-2023-1318

Cross-site Scripting (XSS) - Generic in GitHub repository osticket/osticket prior to v1.16.6.

Fix: 1.16.6+
Fix from $1,600 2023-03-10
Osticket MEDIUM 5.4
CVE-2022-4271

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4.

Fix: 1.16.4+
Fix from $1,600 2022-12-02
Osticket MEDIUM 5.4
CVE-2022-32074

A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889f…

Fix: 2022-05-19+
Fix from $1,600 2022-07-13
Osticket CRITICAL 9.8
CVE-2021-42235

SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile fu…

Fix: 1.14.8 / 1.15.4+
Fix from $2,300 2022-05-04
Osticket MEDIUM 6.1
CVE-2020-22608

Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php.

Fix: 1.12.6+
Fix from $1,600 2021-06-28
Osticket MEDIUM 6.1
CVE-2020-22609

Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.

Fix: 1.12.6+
Fix from $1,600 2021-06-28
Osticket CRITICAL 9.8
CVE-2020-24881EPSS 73%

SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

Fix: 1.14.3+
Fix from $2,300 2020-11-02
Osticket MEDIUM 6.1
CVE-2020-24917

osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.

Fix: 1.14.3+
Fix from $1,600 2020-08-30
Osticket MEDIUM 5.4
CVE-2020-16193

osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.

Fix: 1.14.3+
Fix from $1,600 2020-08-26
Osticket MEDIUM 5.4
CVE-2020-14012

scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent.

No fix yet
Fix from $1,600 2020-06-10
Osticket MEDIUM 5.4
CVE-2020-12629

include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.

Fix: 1.14.2+
Fix from $1,600 2020-05-04
Osticket HIGH 8.8
CVE-2019-14749EPSS 10%

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionali…

Fix: 1.10.7 / 1.12.1+
Fix from $1,950 2019-08-07
Osticket MEDIUM 6.1
CVE-2019-14750EPSS 11%

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input san…

Fix: 1.10.7 / 1.12.1+
Fix from $1,600 2019-08-07
Osticket MEDIUM 5.4
CVE-2019-14748

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries.…

Fix: 1.10.7 / 1.12.1+
Fix from $1,600 2019-08-07
Osticket MEDIUM 6.1
CVE-2019-13397

Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitra…

Mitigation only
Fix from $1,600 2019-07-09
Osticket MEDIUM 6.1
CVE-2019-11537

In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent ma…

Fix: 1.12+
Fix from $1,600 2019-04-25
Osticket HIGH 8.1
CVE-2018-7195

Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging gu…

Fix: after 1.10.1
Fix from $1,950 2018-03-27