Zammad
by Zammad
Source repositories
CVEs (91)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10098 | Med | 0.35 | 5.4 | 0.01 | Mar 5, 2020 | An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Email functionality. The malicious JavaScript will execute within the browser of any user who opens the Ticket with the Article created from that Email. | ||
| CVE-2020-10097 | Med | 0.35 | 5.3 | 0.01 | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal application or infrastructure information. This information could aid attackers in successfully exploiting other vulnerabilities. | ||
| CVE-2023-50456 | Med | 0.34 | 5.3 | 0.00 | Dec 10, 2023 | An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name. | ||
| CVE-2023-50453 | Med | 0.34 | 5.3 | 0.01 | Dec 10, 2023 | An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public. | ||
| CVE-2026-34718 | Med | 0.33 | 6.1 | 0.00 | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for ticket articles was missing proper sanitization of data: ... URI schemes, resulting in storing such malicious content in the database of the Zammad instance. The… | ||
| CVE-2021-42087 | Med | 0.32 | 4.9 | 0.01 | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API. | ||
| CVE-2020-26028 | Med | 0.32 | 4.9 | 0.01 | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets. | ||
| CVE-2025-32359 | Med | 0.31 | 4.8 | 0.00 | Apr 5, 2025 | In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was enforced in Zammad only on the front end… | ||
| CVE-2025-32357 | Med | 0.28 | 4.3 | 0.00 | Apr 5, 2025 | In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for. | ||
| CVE-2024-55578 | Med | 0.28 | 4.3 | 0.00 | Dec 9, 2024 | Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files. | ||
| CVE-2023-50457 | Med | 0.28 | 4.3 | 0.00 | Dec 10, 2023 | An issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge base answers of a ticket, a user could see entries for which they lack permissions. | ||
| CVE-2022-48023 | Med | 0.28 | 4.3 | 0.00 | Feb 3, 2023 | Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of their customer tickets using the Zammad API. This is now corrected in v5.3.1 so that only agents with write permissions may change ticket tags. | ||
| CVE-2022-48022 | Med | 0.28 | 4.3 | 0.01 | Feb 3, 2023 | An issue in the component /api/v1/mentions of Zammad v5.3.0 allows authenticated attackers with agent permissions to view information about tickets they are not authorized to see. | ||
| CVE-2022-40817 | Med | 0.28 | 4.3 | 0.00 | Sep 27, 2022 | Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents were still wrongly able to perform some operations on such tickets, like adding and removing links, tags. and related answers. This issue has been fixed in… | ||
| CVE-2022-27331 | Med | 0.28 | 4.3 | 0.01 | Apr 27, 2022 | An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users. | ||
| CVE-2021-35300 | Med | 0.28 | 4.3 | 0.01 | Jun 28, 2021 | Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page. | ||
| CVE-2020-26034 | Med | 0.28 | 4.3 | 0.01 | Dec 28, 2020 | An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The application responds differently depending on whether the input supplied was… | ||
| CVE-2020-26031 | Med | 0.28 | 4.3 | 0.01 | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions). | ||
| CVE-2020-10104 | Med | 0.28 | 4.3 | 0.01 | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user that may be compromised and used by an attacker to gain unauthorized access. Hashed passwords are returned to the user when visiting a certain URL. | ||
| CVE-2025-32360 | Med | 0.27 | 4.2 | 0.00 | Apr 5, 2025 | In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged in customer was able to see details about shared drafts for their customer tickets in the browser console, which may contain… |
- risk 0.35cvss 5.4epss 0.01
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Email functionality. The malicious JavaScript will execute within the browser of any user who opens the Ticket with the Article created from that Email.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal application or infrastructure information. This information could aid attackers in successfully exploiting other vulnerabilities.
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name.
- risk 0.34cvss 5.3epss 0.01
An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public.
- risk 0.33cvss 6.1epss 0.00
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for ticket articles was missing proper sanitization of data: ... URI schemes, resulting in storing such malicious content in the database of the Zammad instance. The…
- risk 0.32cvss 4.9epss 0.01
An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.
- risk 0.32cvss 4.9epss 0.01
An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.
- risk 0.31cvss 4.8epss 0.00
In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was enforced in Zammad only on the front end…
- risk 0.28cvss 4.3epss 0.00
In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.
- risk 0.28cvss 4.3epss 0.00
Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.
- risk 0.28cvss 4.3epss 0.00
An issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge base answers of a ticket, a user could see entries for which they lack permissions.
- risk 0.28cvss 4.3epss 0.00
Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of their customer tickets using the Zammad API. This is now corrected in v5.3.1 so that only agents with write permissions may change ticket tags.
- risk 0.28cvss 4.3epss 0.01
An issue in the component /api/v1/mentions of Zammad v5.3.0 allows authenticated attackers with agent permissions to view information about tickets they are not authorized to see.
- risk 0.28cvss 4.3epss 0.00
Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents were still wrongly able to perform some operations on such tickets, like adding and removing links, tags. and related answers. This issue has been fixed in…
- risk 0.28cvss 4.3epss 0.01
An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users.
- risk 0.28cvss 4.3epss 0.01
Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.
- risk 0.28cvss 4.3epss 0.01
An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The application responds differently depending on whether the input supplied was…
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user that may be compromised and used by an attacker to gain unauthorized access. Hashed passwords are returned to the user when visiting a certain URL.
- risk 0.27cvss 4.2epss 0.00
In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged in customer was able to see details about shared drafts for their customer tickets in the browser console, which may contain…
Page 4 of 5