Zammad
by Zammad
Source repositories
CVEs (91)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-35298 | Med | 0.40 | 6.1 | 0.01 | Jun 28, 2021 | Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information. | ||
| CVE-2019-1010018 | Med | 0.40 | 6.1 | 0.01 | Jul 16, 2019 | Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The impact is: Execute java script code on users browser. The component is: web app. The attack vector is: the victim must open a ticket. The fixed version is: 2.3.1, 2.2.2 and 2.1.3. | ||
| CVE-2018-1000154 | Med | 0.40 | 6.1 | 0.02 | Apr 5, 2018 | Zammad GmbH Zammad version 2.3.0 and earlier contains a Improper Neutralization of Script-Related HTML Tags in a Web Page (CWE-80) vulnerability in the subject of emails which are not html quoted in certain cases. This can result in the embedding and execution of java script… | ||
| CVE-2017-5621 | Med | 0.40 | 6.1 | 0.01 | Mar 13, 2017 | An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. XSS can be triggered via malicious HTML in a chat message or the content of a ticket article, when using either the REST API or the WebSocket API. | ||
| CVE-2017-5620 | Med | 0.40 | 6.1 | 0.01 | Mar 13, 2017 | An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of getting downloaded. This creates an attack vector of executing code in the domain of the application. | ||
| CVE-2023-50454 | Med | 0.38 | 5.9 | 0.00 | Dec 10, 2023 | An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper validation of hostname and certificate authority. This is exploitable by man-in-the-middle attackers. | ||
| CVE-2026-34248 | Med | 0.37 | 5.7 | 0.00 | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other's tickets) could see fields which are not intended for customers - including fields not intended for them at all (e.g. priority,… | ||
| CVE-2026-34721 | Med | 0.35 | 6.5 | 0.00 | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints for Microsoft, Google, and Facebook external credentials do not validate a CSRF state parameter. This vulnerability is fixed in 7.0.1 and 6.5.4. | ||
| CVE-2021-44886 | Med | 0.35 | 5.3 | 0.01 | Feb 4, 2022 | In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to. | ||
| CVE-2021-42137 | Med | 0.35 | 5.3 | 0.01 | Oct 11, 2021 | An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of tickets that shows title, state, etc. | ||
| CVE-2021-42085 | Med | 0.35 | 5.4 | 0.01 | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar. | ||
| CVE-2021-42092 | Med | 0.35 | 5.4 | 0.01 | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket. | ||
| CVE-2021-35302 | Med | 0.35 | 5.3 | 0.01 | Jun 28, 2021 | Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information. | ||
| CVE-2021-35301 | Med | 0.35 | 5.3 | 0.01 | Jun 28, 2021 | Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view. | ||
| CVE-2020-26035 | Med | 0.35 | 5.4 | 0.01 | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket. | ||
| CVE-2020-26033 | Med | 0.35 | 5.4 | 0.00 | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check. | ||
| CVE-2020-10105 | Med | 0.35 | 5.3 | 0.01 | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an attacker to formulate more precise attacks. Source code was disclosed for the file… | ||
| CVE-2020-10103 | Med | 0.35 | 5.4 | 0.01 | Mar 5, 2020 | An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the File Upload functionality in Zammad. The malicious JavaScript will execute within the browser of any user who opens a specially crafted link to the uploaded… | ||
| CVE-2020-10102 | Med | 0.35 | 5.3 | 0.01 | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. The Forgot Password functionality is implemented in a way that would enable an anonymous user to guess valid user emails. In the current implementation, the application responds differently depending on whether the input… | ||
| CVE-2020-10099 | Med | 0.35 | 5.4 | 0.01 | Mar 5, 2020 | An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Ticket functionality in Zammad. The malicious JavaScript will execute within the browser of any user who opens the ticket or has the ticket within the… |
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information.
- risk 0.40cvss 6.1epss 0.01
Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The impact is: Execute java script code on users browser. The component is: web app. The attack vector is: the victim must open a ticket. The fixed version is: 2.3.1, 2.2.2 and 2.1.3.
- risk 0.40cvss 6.1epss 0.02
Zammad GmbH Zammad version 2.3.0 and earlier contains a Improper Neutralization of Script-Related HTML Tags in a Web Page (CWE-80) vulnerability in the subject of emails which are not html quoted in certain cases. This can result in the embedding and execution of java script…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. XSS can be triggered via malicious HTML in a chat message or the content of a ticket article, when using either the REST API or the WebSocket API.
- risk 0.40cvss 6.1epss 0.01
An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of getting downloaded. This creates an attack vector of executing code in the domain of the application.
- risk 0.38cvss 5.9epss 0.00
An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper validation of hostname and certificate authority. This is exploitable by man-in-the-middle attackers.
- risk 0.37cvss 5.7epss 0.00
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other's tickets) could see fields which are not intended for customers - including fields not intended for them at all (e.g. priority,…
- risk 0.35cvss 6.5epss 0.00
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints for Microsoft, Google, and Facebook external credentials do not validate a CSRF state parameter. This vulnerability is fixed in 7.0.1 and 6.5.4.
- risk 0.35cvss 5.3epss 0.01
In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of tickets that shows title, state, etc.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.
- risk 0.35cvss 5.3epss 0.01
Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information.
- risk 0.35cvss 5.3epss 0.01
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.
- risk 0.35cvss 5.4epss 0.00
An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an attacker to formulate more precise attacks. Source code was disclosed for the file…
- risk 0.35cvss 5.4epss 0.01
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the File Upload functionality in Zammad. The malicious JavaScript will execute within the browser of any user who opens a specially crafted link to the uploaded…
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Zammad 3.0 through 3.2. The Forgot Password functionality is implemented in a way that would enable an anonymous user to guess valid user emails. In the current implementation, the application responds differently depending on whether the input…
- risk 0.35cvss 5.4epss 0.01
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Ticket functionality in Zammad. The malicious JavaScript will execute within the browser of any user who opens the ticket or has the ticket within the…
Page 3 of 5