Vulnerabilities
37 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-26895 | User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform. User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2026-22200 | Arbitrary File Read in osTicket PDF Export via PHP Filter Injection osTicket versions 1.18.x before 1.18.3 and 1.17.x before 1.17.7 contain an arbitrary file read in the ticket PDF export feature: rich-text HTML submitted in a ticket can carry PHP filter expressions that are insufficiently sanitized before being processed by the embedded mPDF PDF generator. An attacker triggers the flaw by submitting a crafted ticket and then exporting that ticket to PDF, at which point the generated PDF embeds the contents of attacker-chosen files from the server filesystem as bitmap images. This yields disclosure of sensitive local files readable by the osTicket application user, and the public technical analysis (Horizon3's 'ticket to shell' writeup) indicates the PHP filter primitive can be pushed toward remote code execution. Affected organizations are those running the listed osTicket versions in default configurations that allow guests to create tickets and view ticket status, or with self-registration enabled. No confirmed in-the-wild exploitation or KEV listing is known yet, but a public PoC exists and EPSS assigns a 73.9% probability of exploitation within 30 days. Do: Upgrade to osTicket 1.18.3 (on the 1.18.x branch) or 1.17.7 (on the 1.17.x branch), which contain the fix. Until patched, restrict guest ticket creation and ticket-status access or disable ticket PDF export, and audit for tickets containing php://filter-style expressions in rich text along with anomalous PDF export activity. Given the public PoC and high EPSS score, treat this as likely to be exploited in the near term. | 8.7 | 74% | PoC |
| large≈10,000–100,000 self-hosted osTicket deployments (estimate) | |
| CVE-2025-26241 | A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL c A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2023-46967 | Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2023-27149 +1 in the same advisory: …27148 | A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payloa A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a custom list. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2021-45811 | A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL com A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination. NVD description · AI analysis pending | 6.5 | 2% | PoC |
| — | |
| CVE-2023-30082 | A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop responding. When a long password is entered, this procedure will consume all available CPU and memory. NVD description · AI analysis pending | 7.5 | <1% | PoC ×2 |
| — | |
| CVE-2022-31890 +1 in the same advisory: …31889 | SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2022-31888 | Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2. Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2. NVD description · AI analysis pending | 8.8 | 1% | PoC |
| — | |
| CVE-2023-1320 | Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6. Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6. NVD description · AI analysis pending | 6.1 group max | <1% | PoC |
| — | |
| CVE-2022-4271 | Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4. Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-32074 | A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file. NVD description · AI analysis pending | 5.4 | 1% |
| — | ||
| CVE-2021-42235 | SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2020-22609 +1 in the same advisory: …22608 | Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php. Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2020-24881 | SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. NVD description · AI analysis pending | 9.8 | 73% | PoC ×2 |
| — | |
| CVE-2020-24917 | osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php. osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php. NVD description · AI analysis pending | 6.1 | 1% |
| — | ||
| CVE-2020-16193 | osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call. osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2020-14012 | scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2020-12629 | include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name. include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name. NVD description · AI analysis pending | 5.4 | 2% | PoC |
| — | |
| CVE-2019-14749 | An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user input in the Name and Internal Notes fields in the Users tab, and the Issue Summary field in the tickets tab. This allows other agents to download data in a .csv file format or .xls file format. This is used as input for spreadsheet applications such as Excel and OpenOffice Calc, resulting in a situation where cells in the spreadsheets can contain input from an untrusted source. As a result, the end user who is accessing the exported spreadsheet can be affected. NVD description · AI analysis pending | 8.8 group max | 10% |
| — | ||
| CVE-2019-13397 | Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file ext Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket. NVD description · AI analysis pending | 6.1 | 1% |
| — | ||
| CVE-2019-11537 | In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can appear in an error message. The XSS can lead to local file inclusion. NVD description · AI analysis pending | 6.1 | 5% | PoC ×3 |
| — | |
| CVE-2018-7195 | Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access and guessing a 6-digit number. NVD description · AI analysis pending | 8.1 group max | <1% | PoC |
| — |