osticket
Enterprise Softwareoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting osticket.
- CVE-2026-36214osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip component and insufficient HTML sanitization, allowing rem...6.4
- CVE-2025-45387osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.5.4
- CVE-2023-1320Cross-site Scripting (XSS) - Stored in osticket/osticket6.1
- CVE-2023-1318Cross-site Scripting (XSS) - Generic in osticket/osticket5.4
- CVE-2023-1317Cross-site Scripting (XSS) - Reflected in osticket/osticket5.4
- CVE-2023-1319Cross-site Scripting (XSS) - Stored in osticket/osticket4.8
- CVE-2023-1316Cross-site Scripting (XSS) - Stored in osticket/osticket5.4
- CVE-2023-1315Cross-site Scripting (XSS) - Reflected in osticket/osticket5.4
- CVE-2022-4271Cross-site Scripting (XSS) - Reflected in osticket/osticket5.4
- CVE-2017-15580osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such ...9.8
- CVE-2017-15362osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link, aka XSS. Session ID and data theft may follow as well as ...6.1
- CVE-2017-14396In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.9.8
- CVE-2010-0606Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly relat...3.5
- CVE-2010-0605SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.7.5
- CVE-2006-6733Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web script or HTML via the e parameter.4.3