Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Osticket MEDIUM 5.4
CVE-2025-45387

osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.

Fix: 1.17.6 / 1.18.2+
Fix from $1,600 2025-06-02
Osticket CRITICAL 9.8
CVE-2017-15580EPSS 16%

osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's c…

No fix yet
Fix from $2,300 2017-10-23
Osticket MEDIUM 6.1
CVE-2017-15362

osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link, aka XSS. …

Mitigation only
Fix from $1,600 2017-10-16
Osticket CRITICAL 9.8
CVE-2017-14396

In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstra…

Patch available
Fix from $2,300 2017-09-12
Osticket Sts HIGH 7.5
CVE-2005-2153

SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the …

No fix yet
Fix from $1,950 2005-07-06
Osticket Sts HIGH 7.5
CVE-2005-2154

PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and pos…

No fix yet
Fix from $1,950 2005-07-06
Osticket HIGH 7.5
CVE-2005-1437

Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admin.php or …

No fix yet
Fix from $1,950 2005-05-03
Osticket HIGH 7.5
CVE-2005-1438

PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter.

Mitigation only
Fix from $1,950 2005-05-03
Osticket Sts HIGH 7.5
CVE-2004-0613EPSS 10%

osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to …

Patch available
Fix from $1,950 2004-12-06
Osticket Sts MEDIUM 6.4
CVE-2004-0614

osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload a file of…

Mitigation only
Fix from $1,600 2004-12-06