Skip to main content

Vendor archive

otrs CVEs

Beta · best-effort

159 CVEs tagged to vendor otrs2 Critical, 21 High, 101 Medium, 35 Low, 0 Unrated.

CVE-2026-48209

Published Jun 1, 2026

An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform reflected cross-site scriptin…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48208

Published Jun 1, 2026

An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48191

Published Jun 1, 2026

An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Meta Filters modules allows gaining knowledge about number of…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48190

Published Jun 1, 2026

An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated customer to query the system for CI information. Please note…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48189

Published Jun 1, 2026

An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups. Please note that the feature…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48188

Published Jun 1, 2026

An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48187

Published Jun 1, 2026

An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the abortion of the webserver.Thi…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48210

Published May 31, 2026

An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabli…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24387

Published Mar 10, 2025

A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-6540

Published Jul 15, 2024

Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS could allow an authorized user to download a list of tickets c…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23794

Published Jul 15, 2024

An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an agent with read-only permissions…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23792

Published Jan 29, 2024

When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23791

Published Jan 29, 2024

Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issue affects OTRS: from 7.0.X thr…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23790

Published Jan 29, 2024

Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-6254

Published Nov 27, 2023

A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the server response- This issue affect…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5422

Published Oct 16, 2023

The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_get_verify_result() function i…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5421

Published Oct 16, 2023

An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate the CustomerID field to execute JavaScript code that runs im…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-38059

Published Oct 16, 2023

The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to retreive the IP of the user.This…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38060

Published Jul 24, 2023

Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic Interface modules allows any a…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38058

Published Jul 24, 2023

An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the neede…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38057

Published Jul 24, 2023

An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text a…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38056

Published Jul 24, 2023

Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker wit…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2534

Published May 8, 2023

Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into ove…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17883

Published Apr 16, 2023

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1250

Published Mar 20, 2023

Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 159 CVEsPage 1 of 7