VYPR
Vendor

Bestpractical

Products
11
CVEs
85
Across products
120
Status
Private

Products

11

Recent CVEs

85
View all 85 CVEs →
  • CVE-2026-44231CriJul 20, 2026
    risk 0.59cvss 9.1epss 0.00

    RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain…

  • CVE-2022-25801CriJul 14, 2022
    risk 0.59cvss 9.1epss 0.01

    Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.

  • CVE-2022-25800CriJul 14, 2022
    risk 0.59cvss 9.1epss 0.01

    Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.

  • CVE-2025-15646CriJul 1, 2026
    risk 0.57cvss 9.8epss 0.01

    HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the element was added to libgumbo 0.10.0 in 2015, but the walk_tree function in lib/HTML/Gumbo.xs was not updated to support it. The element was treated as a text-node,…

  • CVE-2017-5944HigJul 3, 2017
    risk 0.57cvss 8.8epss 0.03

    The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute arbitrary code via a crafted saved search name.

  • CVE-2017-5943HigJul 3, 2017
    risk 0.57cvss 8.8epss 0.01

    Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cross-site request forgery (CSRF) verification tokens via a crafted URL.

  • CVE-2026-41075HigMay 22, 2026
    risk 0.50cvss 8.8epss 0.00

    RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft input that is incorporated into database queries without proper validation,…

  • CVE-2023-45024HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.

  • CVE-2023-41260HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.

  • CVE-2023-41259HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.

  • CVE-2018-18898HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.02

    The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.

  • CVE-2025-31501HigMay 28, 2025
    risk 0.47cvss 7.2epss 0.00

    Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.

  • CVE-2025-31500HigMay 28, 2025
    risk 0.47cvss 7.2epss 0.00

    Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.

  • CVE-2025-30087HigMay 28, 2025
    risk 0.47cvss 7.2epss 0.00

    Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.

  • CVE-2026-41076HigMay 22, 2026
    risk 0.46cvss 8.1epss 0.00

    RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass vulnerability in RT installations that use LDAP/AD for user authentication. Under certain LDAP server…

  • CVE-2026-44230MedJul 20, 2026
    risk 0.40cvss 6.1epss 0.00

    RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT…

  • CVE-2026-44227MedJul 20, 2026
    risk 0.40cvss 6.1epss 0.00

    RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary…

  • CVE-2022-25803MedJul 14, 2022
    risk 0.40cvss 6.1epss 0.01

    Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.

  • CVE-2022-25802MedJul 14, 2022
    risk 0.40cvss 6.1epss 0.01

    Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.

  • CVE-2016-6127MedJul 3, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownloadAttachments config setting is not in use, allows remote attackers to inject arbitrary web script or HTML via a file upload with…