VYPR

osTicket

by Enhancesoft LLC

CVEs (3)

  • CVE-2026-22200HigJan 12, 2026
    risk 0.58cvss 7.5epss 0.74

    Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which…

  • CVE-2026-9507MedJun 16, 2026
    risk 0.33cvss epss 0.00

    A session fixation vulnerability has been identified in osTicket v1.18.2. This security flaw allows an attacker to hijack a victim’s account by keeping the initial session identifier (OSTSESSID) active after a successful login. The issue lies in the fact that the…

  • CVE-2026-18363CriJul 30, 2026
    risk 0.00cvss epss 0.00

    A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured…