Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Znuny CRITICAL 9.8
CVE-2025-26846

An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata.

Fix: after 7.1.3
Fix from $2,300 2025-05-12
Znuny CRITICAL 9.8
CVE-2025-26845

An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command e…

Fix: after 7.1.3
Fix from $2,300 2025-05-08
Znuny HIGH 7.5
CVE-2025-26847

An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.

Fix: after 7.1.6
Fix from $1,950 2025-05-08
Znuny MEDIUM 6.1
CVE-2025-43926

An issue was discovered in Znuny through 6.5.14 and 7.x through 7.1.6. Custom AJAX calls to the AgentPreferences UpdateAJAX subaction can be used to …

Fix: after 7.1.6
Fix from $1,600 2025-05-08
Znuny CRITICAL 9.8
CVE-2025-26844

An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.

Fix: after 7.1.3
Fix from $2,300 2025-05-08
Znuny HIGH 7.5
CVE-2025-26842

An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to use…

Fix: after 7.1.3
Fix from $1,950 2025-05-08
Znuny HIGH 7.5
CVE-2024-48938

Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied fr…

Fix: 6.1.0+
Fix from $1,950 2024-10-11
Znuny MEDIUM 6.1
CVE-2024-48937

Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dial…

Fix: 6.1.0+
Fix from $1,600 2024-10-11
Znuny CRITICAL 9.8
CVE-2024-32491

An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file (via a ma…

Fix: after 7.0.16
Fix from $2,300 2024-04-29
Znuny HIGH 8.8
CVE-2024-32493

An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft fo…

Fix: after 7.0.16
Fix from $1,950 2024-04-29
Znuny HIGH 7.1
CVE-2024-32492

An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the execution of external JavaScript.

Fix: after 7.0.16
Fix from $1,950 2024-04-29