VYPR
Vendor

Osticket

Products
2
CVEs
66
Across products
68
Status
Private

Products

2

Recent CVEs

66
View all 66 CVEs →
  • CVE-2020-24881CriNov 2, 2020
    risk 0.73cvss 9.8epss 0.73

    SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

  • CVE-2017-15580CriOct 23, 2017
    risk 0.68cvss 9.8epss 0.16

    osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a…

  • CVE-2019-14749HigAug 7, 2019
    risk 0.61cvss 8.8epss 0.10

    An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user input in the Name and Internal Notes fields…

  • CVE-2017-14396CriSep 12, 2017
    risk 0.60cvss 9.8epss 0.03

    In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.

  • CVE-2026-22200HigJan 12, 2026
    risk 0.58cvss 7.5epss 0.73

    Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which…

  • CVE-2026-38447CriAug 3, 2026
    risk 0.57cvss 9.8epss 0.00

    osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and…

  • CVE-2018-7195HigMar 27, 2018
    risk 0.53cvss 8.1epss 0.01

    Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access and guessing a 6-digit number.

  • CVE-2023-30082HigJun 14, 2023
    risk 0.49cvss 7.5epss 0.01

    A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop responding. When a long password is entered, this procedure…

  • CVE-2019-14750MedAug 7, 2019
    risk 0.44cvss 6.1epss 0.11

    An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields…

  • CVE-2019-11537MedApr 25, 2019
    risk 0.43cvss 6.1epss 0.05

    In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can appear in an error message. The XSS can…

  • CVE-2025-26241MedMay 5, 2025
    risk 0.42cvss 6.5epss 0.00

    A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

  • CVE-2021-45811MedSep 8, 2023
    risk 0.42cvss 6.5epss 0.02

    A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

  • CVE-2023-46967MedFeb 20, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.

  • CVE-2020-24917MedAug 30, 2020
    risk 0.40cvss 6.1epss 0.01

    osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.

  • CVE-2019-13397MedJul 9, 2019
    risk 0.40cvss 6.1epss 0.01

    Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.

  • CVE-2018-7196MedMar 27, 2018
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" parameter.

  • CVE-2018-7193MedMar 27, 2018
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" parameter.

  • CVE-2018-7192MedMar 27, 2018
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "message" parameter.

  • CVE-2017-15362MedOct 16, 2017
    risk 0.40cvss 6.1epss 0.01

    osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link, aka XSS. Session ID and data theft may follow as well as the possibility of bypassing CSRF protections, injection of iframes to establish…

  • CVE-2019-14748MedAug 7, 2019
    risk 0.38cvss 5.4epss 0.03

    An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implemented for file content checks; also, the…