← Back

Otrs

otrs

Vendor: Otrs • 142 CVEs

CVEs (142)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Otrs
1Otrs
Jun 17, 2026
Jul 24, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Cod...Show more
Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34. Show less
1Otrs
1Otrs
Jun 17, 2026
May 8, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be...Show more
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be correlated with real names e. g. via ticket histories by any user. (Fuzzing for garnering other adjacent user/sensitive data). Subscribing to all possible push events could also lead to performance implications on the server side, depending on the size of the installation and the number of active users. (Flooding)This issue affects OTRS: from 8.0.X before 8.0.32. Show less
1Otrs
1Otrs
Feb 6, 2025
Apr 16, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it cou...Show more
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS.Show less
1Otrs
1Otrs
Jun 17, 2026
Mar 20, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that g...Show more
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated comments and ACL-names This issue affects OTRS: from 7.0.X before 7.0.42, from 8.0.X before 8.0.31; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34. Show less
1Otrs
1Otrs
Jun 17, 2026
Mar 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Improper Input Validation vulnerability in OTRS AG OTRS (Ticket Actions modules), OTRS AG ((OTRS)) Community Edition (Ticket Actions modules) allows Cross-Site Scripting (XSS).This issue affects OTRS: from 7.0.X before 7...Show more
Improper Input Validation vulnerability in OTRS AG OTRS (Ticket Actions modules), OTRS AG ((OTRS)) Community Edition (Ticket Actions modules) allows Cross-Site Scripting (XSS).This issue affects OTRS: from 7.0.X before 7.0.42; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34. Show less
1Otrs
1Otrs
Jun 17, 2026
Dec 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This issue affects OTRS: from 7.0.1 before 7.0.40 Patch 1, from 8.0.1 before 8....Show more
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This issue affects OTRS: from 7.0.1 before 7.0.40 Patch 1, from 8.0.1 before 8.0.28 Patch 1; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.Show less
1Otrs
1Otrs
Jun 17, 2026
Oct 17, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Article template contents with sensitive data could be accessed from agents without permissions.
1Otrs
1Otrs
Jun 17, 2026
Oct 17, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the system
1Otrs
1Otrs
Jun 17, 2026
Sep 5, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package
1Otrs
1Otrs
Jun 17, 2026
Sep 5, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is execut...Show more
An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldapShow less
1Otrs
1Otrs
Jun 17, 2026
Sep 5, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS.
1Otrs
1Otrs
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.
1Otrs
1Otrs
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
A reply to a forwarded email article by a 3rd party could unintensionally expose the email content to the ticket customer under certain circumstances.
1Otrs
2Calendar Resource Planning
Otrs
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received ICS file contains OTRS release number.
1Otrs
1Otrs
Jun 17, 2026
Mar 21, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###AccountedTimeDisplay is disabled.
1Otrs
1Otrs
Jun 17, 2026
Mar 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and pr...Show more
Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and prior versions, 8.0.x version: 8.0.19 and prior versions.Show less
1Otrs
3Otrs
Otrs ItsmOtrs Storm
Jun 17, 2026
Mar 21, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Specially crafted string in OTRS system configuration can allow the execution of any system command.
1Otrs
1Otrs
Jun 17, 2026
Feb 7, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular expression check. When used in the agent interface, malicious code might be exectued in the browser...Show more
OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular expression check. When used in the agent interface, malicious code might be exectued in the browser. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.31 and prior versions.Show less
1Otrs
1Otrs
Jun 17, 2026
Oct 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS...Show more
Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.Show less
1Otrs
1Otrs
Jun 17, 2026
Sep 6, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version...Show more
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior versions.Show less