VYPR

Zammad

by Zammad

Source repositories

CVEs (91)

  • CVE-2020-10098MedMar 5, 2020
    risk 0.35cvss 5.4epss 0.01

    An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Email functionality. The malicious JavaScript will execute within the browser of any user who opens the Ticket with the Article created from that Email.

  • CVE-2020-10097MedMar 5, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal application or infrastructure information. This information could aid attackers in successfully exploiting other vulnerabilities.

  • CVE-2023-50456MedDec 10, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name.

  • CVE-2023-50453MedDec 10, 2023
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public.

  • CVE-2026-34718MedApr 8, 2026
    risk 0.33cvss 6.1epss 0.00

    Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for ticket articles was missing proper sanitization of data: ... URI schemes, resulting in storing such malicious content in the database of the Zammad instance. The…

  • CVE-2021-42087MedOct 7, 2021
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.

  • CVE-2020-26028MedDec 28, 2020
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.

  • CVE-2025-32359MedApr 5, 2025
    risk 0.31cvss 4.8epss 0.00

    In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was enforced in Zammad only on the front end…

  • CVE-2025-32357MedApr 5, 2025
    risk 0.28cvss 4.3epss 0.00

    In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.

  • CVE-2024-55578MedDec 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.

  • CVE-2023-50457MedDec 10, 2023
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge base answers of a ticket, a user could see entries for which they lack permissions.

  • CVE-2022-48023MedFeb 3, 2023
    risk 0.28cvss 4.3epss 0.00

    Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of their customer tickets using the Zammad API. This is now corrected in v5.3.1 so that only agents with write permissions may change ticket tags.

  • CVE-2022-48022MedFeb 3, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue in the component /api/v1/mentions of Zammad v5.3.0 allows authenticated attackers with agent permissions to view information about tickets they are not authorized to see.

  • CVE-2022-40817MedSep 27, 2022
    risk 0.28cvss 4.3epss 0.00

    Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents were still wrongly able to perform some operations on such tickets, like adding and removing links, tags. and related answers. This issue has been fixed in…

  • CVE-2022-27331MedApr 27, 2022
    risk 0.28cvss 4.3epss 0.01

    An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users.

  • CVE-2021-35300MedJun 28, 2021
    risk 0.28cvss 4.3epss 0.01

    Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.

  • CVE-2020-26034MedDec 28, 2020
    risk 0.28cvss 4.3epss 0.01

    An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The application responds differently depending on whether the input supplied was…

  • CVE-2020-26031MedDec 28, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).

  • CVE-2020-10104MedMar 5, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user that may be compromised and used by an attacker to gain unauthorized access. Hashed passwords are returned to the user when visiting a certain URL.

  • CVE-2025-32360MedApr 5, 2025
    risk 0.27cvss 4.2epss 0.00

    In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged in customer was able to see details about shared drafts for their customer tickets in the browser console, which may contain…

Page 4 of 5