VYPR

((OTRS)) Community Edition

by OTRS

CVEs (2)

  • CVE-2026-48188CriJun 1, 2026
    risk 0.59cvss 9.1epss

    An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the system if the MySQL/MariaDB server is configured with the…

  • CVE-2026-48209HigJun 1, 2026
    risk 0.46cvss 7.1epss

    An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform reflected cross-site scripting (XSS) attacks via crafted request parameters associated with ticket actions. By injecting…