Vendor CVEs
Zammad
All CVEs
91 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-42085 | Med | 0.35 | 5.4 | 0.01 | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar. | ||
| CVE-2021-42092 | Med | 0.35 | 5.4 | 0.01 | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket. | ||
| CVE-2021-35302 | Med | 0.35 | 5.3 | 0.01 | Jun 28, 2021 | Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information. | ||
| CVE-2021-35301 | Med | 0.35 | 5.3 | 0.01 | Jun 28, 2021 | Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view. | ||
| CVE-2020-26035 | Med | 0.35 | 5.4 | 0.01 | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket. | ||
| CVE-2020-26033 | Med | 0.35 | 5.4 | 0.00 | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check. | ||
| CVE-2020-10105 | Med | 0.35 | 5.3 | 0.01 | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an attacker to formulate more precise attacks. Source code was disclosed for the file… | ||
| CVE-2020-10103 | Med | 0.35 | 5.4 | 0.01 | Mar 5, 2020 | An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the File Upload functionality in Zammad. The malicious JavaScript will execute within the browser of any user who opens a specially crafted link to the uploaded… | ||
| CVE-2020-10102 | Med | 0.35 | 5.3 | 0.01 | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. The Forgot Password functionality is implemented in a way that would enable an anonymous user to guess valid user emails. In the current implementation, the application responds differently depending on whether the input… | ||
| CVE-2020-10099 | Med | 0.35 | 5.4 | 0.01 | Mar 5, 2020 | An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Ticket functionality in Zammad. The malicious JavaScript will execute within the browser of any user who opens the ticket or has the ticket within the… | ||
| CVE-2020-10098 | Med | 0.35 | 5.4 | 0.01 | Mar 5, 2020 | An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Email functionality. The malicious JavaScript will execute within the browser of any user who opens the Ticket with the Article created from that Email. | ||
| CVE-2020-10097 | Med | 0.35 | 5.3 | 0.01 | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal application or infrastructure information. This information could aid attackers in successfully exploiting other vulnerabilities. | ||
| CVE-2023-50456 | Med | 0.34 | 5.3 | 0.00 | Dec 10, 2023 | An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name. | ||
| CVE-2023-50453 | Med | 0.34 | 5.3 | 0.01 | Dec 10, 2023 | An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public. | ||
| CVE-2026-34718 | Med | 0.33 | 6.1 | 0.00 | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for ticket articles was missing proper sanitization of data: ... URI schemes, resulting in storing such malicious content in the database of the Zammad instance. The… | ||
| CVE-2021-42087 | Med | 0.32 | 4.9 | 0.01 | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API. | ||
| CVE-2020-26028 | Med | 0.32 | 4.9 | 0.01 | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets. | ||
| CVE-2025-32359 | Med | 0.31 | 4.8 | 0.00 | Apr 5, 2025 | In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was enforced in Zammad only on the front end… | ||
| CVE-2025-32357 | Med | 0.28 | 4.3 | 0.00 | Apr 5, 2025 | In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for. | ||
| CVE-2024-55578 | Med | 0.28 | 4.3 | 0.00 | Dec 9, 2024 | Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files. | ||
| CVE-2023-50457 | Med | 0.28 | 4.3 | 0.00 | Dec 10, 2023 | An issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge base answers of a ticket, a user could see entries for which they lack permissions. | ||
| CVE-2022-48023 | Med | 0.28 | 4.3 | 0.00 | Feb 3, 2023 | Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of their customer tickets using the Zammad API. This is now corrected in v5.3.1 so that only agents with write permissions may change ticket tags. | ||
| CVE-2022-48022 | Med | 0.28 | 4.3 | 0.01 | Feb 3, 2023 | An issue in the component /api/v1/mentions of Zammad v5.3.0 allows authenticated attackers with agent permissions to view information about tickets they are not authorized to see. | ||
| CVE-2022-40817 | Med | 0.28 | 4.3 | 0.00 | Sep 27, 2022 | Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents were still wrongly able to perform some operations on such tickets, like adding and removing links, tags. and related answers. This issue has been fixed in… | ||
| CVE-2022-27331 | Med | 0.28 | 4.3 | 0.01 | Apr 27, 2022 | An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users. | ||
| CVE-2021-35300 | Med | 0.28 | 4.3 | 0.01 | Jun 28, 2021 | Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page. | ||
| CVE-2020-26034 | Med | 0.28 | 4.3 | 0.01 | Dec 28, 2020 | An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The application responds differently depending on whether the input supplied was… | ||
| CVE-2020-26031 | Med | 0.28 | 4.3 | 0.01 | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions). | ||
| CVE-2020-10104 | Med | 0.28 | 4.3 | 0.01 | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user that may be compromised and used by an attacker to gain unauthorized access. Hashed passwords are returned to the user when visiting a certain URL. | ||
| CVE-2025-32360 | Med | 0.27 | 4.2 | 0.00 | Apr 5, 2025 | In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged in customer was able to see details about shared drafts for their customer tickets in the browser console, which may contain… | ||
| CVE-2025-32358 | Med | 0.26 | 4.0 | 0.00 | Apr 5, 2025 | In Zammad 6.4.x before 6.4.2, SSRF can occur. Authenticated admin users can enable webhooks in Zammad, which are triggered as POST requests when certain conditions are met. If a webhook endpoint returned a redirect response, Zammad would follow it automatically with another GET… | ||
| CVE-2026-34837 | Med | 0.21 | 4.3 | 0.00 | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_assistance/text_tools/:id contains an authorization failure. Context data (e.g., a group or organization) supplied to be used in the AI prompt were not checked if… | ||
| CVE-2026-34782 | Med | 0.21 | 4.3 | 0.00 | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the REST endpoint POST /api/v1/ai_assistance/text_tools/:id was not checking if a user is privileged to use the text tool, resulting in being able to use it in all situations. This… | ||
| CVE-2026-34722 | Med | 0.21 | 4.3 | 0.00 | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the used endpoint for ticket creation was missing authorization if the related parameter for adding links is used. This vulnerability is fixed in 7.0.1 and 6.5.4. | ||
| CVE-2026-34720 | Med | 0.21 | 4.3 | 0.00 | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the SSO mechanism in Zammad was not verifying the header originates from a trusted SSO proxy/gateway before applying further actions on it. This vulnerability is fixed in 7.0.1 and… | ||
| CVE-2026-34719 | Med | 0.21 | 4.3 | 0.00 | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was missing a proper validation for loop back addresses, or link-local addresses — only the URL scheme (HTTP/HTTPS) as well as the hostname was checked. This could… | ||
| CVE-2020-29160 | Hig | 0.00 | 7.5 | 0.01 | Dec 28, 2020 | An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing. | ||
| CVE-2020-29159 | Med | 0.00 | 4.9 | 0.01 | Dec 28, 2020 | An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Role, if configured by an admin. This behvaior was unintended. | ||
| CVE-2020-29158 | Med | 0.00 | 4.3 | 0.01 | Dec 28, 2020 | An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view. | ||
| CVE-2020-14214 | Med | 0.00 | 6.5 | 0.01 | Jun 16, 2020 | Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decisions. An attacker can register a new account that will have access to all tickets of an arbitrary Organization. | ||
| CVE-2020-14213 | Med | 0.00 | 5.4 | 0.01 | Jun 16, 2020 | In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data, split, or merge). |
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.
- risk 0.35cvss 5.3epss 0.01
Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information.
- risk 0.35cvss 5.3epss 0.01
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.
- risk 0.35cvss 5.4epss 0.00
An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an attacker to formulate more precise attacks. Source code was disclosed for the file…
- risk 0.35cvss 5.4epss 0.01
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the File Upload functionality in Zammad. The malicious JavaScript will execute within the browser of any user who opens a specially crafted link to the uploaded…
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Zammad 3.0 through 3.2. The Forgot Password functionality is implemented in a way that would enable an anonymous user to guess valid user emails. In the current implementation, the application responds differently depending on whether the input…
- risk 0.35cvss 5.4epss 0.01
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Ticket functionality in Zammad. The malicious JavaScript will execute within the browser of any user who opens the ticket or has the ticket within the…
- risk 0.35cvss 5.4epss 0.01
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Email functionality. The malicious JavaScript will execute within the browser of any user who opens the Ticket with the Article created from that Email.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal application or infrastructure information. This information could aid attackers in successfully exploiting other vulnerabilities.
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name.
- risk 0.34cvss 5.3epss 0.01
An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public.
- risk 0.33cvss 6.1epss 0.00
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for ticket articles was missing proper sanitization of data: ... URI schemes, resulting in storing such malicious content in the database of the Zammad instance. The…
- risk 0.32cvss 4.9epss 0.01
An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.
- risk 0.32cvss 4.9epss 0.01
An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.
- risk 0.31cvss 4.8epss 0.00
In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was enforced in Zammad only on the front end…
- risk 0.28cvss 4.3epss 0.00
In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.
- risk 0.28cvss 4.3epss 0.00
Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.
- risk 0.28cvss 4.3epss 0.00
An issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge base answers of a ticket, a user could see entries for which they lack permissions.
- risk 0.28cvss 4.3epss 0.00
Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of their customer tickets using the Zammad API. This is now corrected in v5.3.1 so that only agents with write permissions may change ticket tags.
- risk 0.28cvss 4.3epss 0.01
An issue in the component /api/v1/mentions of Zammad v5.3.0 allows authenticated attackers with agent permissions to view information about tickets they are not authorized to see.
- risk 0.28cvss 4.3epss 0.00
Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents were still wrongly able to perform some operations on such tickets, like adding and removing links, tags. and related answers. This issue has been fixed in…
- risk 0.28cvss 4.3epss 0.01
An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users.
- risk 0.28cvss 4.3epss 0.01
Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.
- risk 0.28cvss 4.3epss 0.01
An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The application responds differently depending on whether the input supplied was…
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user that may be compromised and used by an attacker to gain unauthorized access. Hashed passwords are returned to the user when visiting a certain URL.
- risk 0.27cvss 4.2epss 0.00
In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged in customer was able to see details about shared drafts for their customer tickets in the browser console, which may contain…
- risk 0.26cvss 4.0epss 0.00
In Zammad 6.4.x before 6.4.2, SSRF can occur. Authenticated admin users can enable webhooks in Zammad, which are triggered as POST requests when certain conditions are met. If a webhook endpoint returned a redirect response, Zammad would follow it automatically with another GET…
- risk 0.21cvss 4.3epss 0.00
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_assistance/text_tools/:id contains an authorization failure. Context data (e.g., a group or organization) supplied to be used in the AI prompt were not checked if…
- risk 0.21cvss 4.3epss 0.00
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the REST endpoint POST /api/v1/ai_assistance/text_tools/:id was not checking if a user is privileged to use the text tool, resulting in being able to use it in all situations. This…
- risk 0.21cvss 4.3epss 0.00
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the used endpoint for ticket creation was missing authorization if the related parameter for adding links is used. This vulnerability is fixed in 7.0.1 and 6.5.4.
- risk 0.21cvss 4.3epss 0.00
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the SSO mechanism in Zammad was not verifying the header originates from a trusted SSO proxy/gateway before applying further actions on it. This vulnerability is fixed in 7.0.1 and…
- risk 0.21cvss 4.3epss 0.00
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was missing a proper validation for loop back addresses, or link-local addresses — only the URL scheme (HTTP/HTTPS) as well as the hostname was checked. This could…
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.
- risk 0.00cvss 4.9epss 0.01
An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Role, if configured by an admin. This behvaior was unintended.
- risk 0.00cvss 4.3epss 0.01
An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view.
- risk 0.00cvss 6.5epss 0.01
Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decisions. An attacker can register a new account that will have access to all tickets of an arbitrary Organization.
- risk 0.00cvss 5.4epss 0.01
In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data, split, or merge).
Page 2 of 2