Skip to main content

Vendor/product archive

enhancesoft / osticket CVEs

Beta · best-effort

45 CVEs tagged to enhancesoft / osticket2 Critical, 9 High, 33 Medium, 1 Low, 0 Unrated.

CVE-2026-26895

Published Apr 2, 2026

User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22200

Published Jan 12, 2026

Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attac…

CVSS 8.7 · High
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2025-26241

Published May 5, 2025

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "ke…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-46967

Published Feb 20, 2024

Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27149

Published Oct 23, 2023

A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27148

Published Oct 23, 2023

A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payloa…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45811

Published Sep 8, 2023

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keyw…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30082

Published Jun 14, 2023

A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31888

Published Apr 5, 2023

Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1320

Published Mar 10, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1319

Published Mar 10, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1318

Published Mar 10, 2023

Cross-site Scripting (XSS) - Generic in GitHub repository osticket/osticket prior to v1.16.6.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1317

Published Mar 10, 2023

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1316

Published Mar 10, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1315

Published Mar 10, 2023

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4271

Published Dec 2, 2022

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32074

Published Jul 13, 2022

A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae al…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2021-42235

Published May 4, 2022

SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-22609

Published Jun 28, 2021

Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-22608

Published Jun 28, 2021

Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14012

Published Jun 10, 2020

scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 45 CVEsPage 1 of 2