← Back

Osticket

osticket

Vendor: Enhancesoft • 22 CVEs

CVEs (22)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Enhancesoft
1Osticket
Apr 7, 2026
Apr 2, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.
1Enhancesoft
1Osticket
Jan 27, 2026
Jan 12, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafte...Show more
Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled.Show less
1Enhancesoft
1Osticket
Apr 25, 2025
Feb 20, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.
1Enhancesoft
1Osticket
Nov 21, 2024
Oct 23, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a cu...Show more
A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a custom list.Show less
1Enhancesoft
1Osticket
Nov 21, 2024
Oct 23, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Role Name parameter.
1Enhancesoft
1Osticket
Nov 21, 2024
Sep 8, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combi...Show more
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.Show less
1Enhancesoft
1Osticket
Jan 6, 2025
Jun 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop r...Show more
A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop responding. When a long password is entered, this procedure will consume all available CPU and memory.Show less
1Enhancesoft
1Osticket
Feb 13, 2025
Apr 5, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.
1Enhancesoft
1Osticket
Nov 21, 2024
Mar 10, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.
1Enhancesoft
1Osticket
Nov 21, 2024
Mar 10, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.
1Enhancesoft
1Osticket
Nov 21, 2024
Mar 10, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Generic in GitHub repository osticket/osticket prior to v1.16.6.
1Enhancesoft
1Osticket
Nov 21, 2024
Mar 10, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.
1Enhancesoft
1Osticket
Nov 21, 2024
Mar 10, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.
1Enhancesoft
1Osticket
Nov 21, 2024
Mar 10, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.
1Enhancesoft
1Osticket
Nov 21, 2024
Dec 2, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4.
1Enhancesoft
1Osticket
Nov 21, 2024
May 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.
1Enhancesoft
1Osticket
Nov 21, 2024
Jun 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.
1Enhancesoft
1Osticket
Nov 21, 2024
Jun 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php.
1Enhancesoft
1Osticket
Nov 21, 2024
Jun 10, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent.
1Enhancesoft
1Osticket
Nov 21, 2024
May 4, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.