ZeroHour

Vulnerabilities

37 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-26895
User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.

User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.

NVD description · AI analysis pending
5.3<1% PoC
  • enhancesoft osticket
CVE-2026-22200
Arbitrary File Read in osTicket PDF Export via PHP Filter Injection

osTicket versions 1.18.x before 1.18.3 and 1.17.x before 1.17.7 contain an arbitrary file read in the ticket PDF export feature: rich-text HTML submitted in a ticket can carry PHP filter expressions that are insufficiently sanitized before being processed by the embedded mPDF PDF generator. An attacker triggers the flaw by submitting a crafted ticket and then exporting that ticket to PDF, at which point the generated PDF embeds the contents of attacker-chosen files from the server filesystem as bitmap images. This yields disclosure of sensitive local files readable by the osTicket application user, and the public technical analysis (Horizon3's 'ticket to shell' writeup) indicates the PHP filter primitive can be pushed toward remote code execution. Affected organizations are those running the listed osTicket versions in default configurations that allow guests to create tickets and view ticket status, or with self-registration enabled. No confirmed in-the-wild exploitation or KEV listing is known yet, but a public PoC exists and EPSS assigns a 73.9% probability of exploitation within 30 days.

Do: Upgrade to osTicket 1.18.3 (on the 1.18.x branch) or 1.17.7 (on the 1.17.x branch), which contain the fix. Until patched, restrict guest ticket creation and ticket-status access or disable ticket PDF export, and audit for tickets containing php://filter-style expressions in rich text along with anomalous PDF export activity. Given the public PoC and high EPSS score, treat this as likely to be exploited in the near term.

8.774% PoC
  • Enhancesoft osTicket 1.18.x prior to 1.18.3
  • Enhancesoft osTicket 1.17.x prior to 1.17.7
large≈10,000–100,000 self-hosted osTicket deployments (estimate)
CVE-2025-26241
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL c

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

NVD description · AI analysis pending
6.5<1% PoC
  • enhancesoft osticket
CVE-2023-46967
Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support

Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.

NVD description · AI analysis pending
6.1<1% PoC
  • enhancesoft osticket
CVE-2023-27149
+1 in the same advisory: …27148
A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payloa

A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a custom list.

NVD description · AI analysis pending
4.8<1% PoC
  • enhancesoft osticket
CVE-2021-45811
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL com

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

NVD description · AI analysis pending
6.52% PoC
  • enhancesoft osticket
CVE-2023-30082
A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket

A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop responding. When a long password is entered, this procedure will consume all available CPU and memory.

NVD description · AI analysis pending
7.5<1% PoC ×2
  • enhancesoft osticket
CVE-2022-31890
+1 in the same advisory: …31889
SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter

SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • enhancesoft audit log
CVE-2022-31888
Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.

Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.

NVD description · AI analysis pending
8.81% PoC
  • enhancesoft osticket
CVE-2023-1320
Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.

Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • enhancesoft osticket
CVE-2022-4271
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4.

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4.

NVD description · AI analysis pending
5.4<1% PoC
  • enhancesoft osticket
CVE-2022-32074
A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb

A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.

NVD description · AI analysis pending
5.41%
  • enhancesoft osticket
CVE-2021-42235
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality

SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.

NVD description · AI analysis pending
9.81%
  • enhancesoft osticket
CVE-2020-22609
+1 in the same advisory: …22608
Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.

Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.

NVD description · AI analysis pending
6.1<1%
  • enhancesoft osticket
CVE-2020-24881
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

NVD description · AI analysis pending
9.873% PoC ×2
  • enhancesoft osticket
CVE-2020-24917
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.

osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.

NVD description · AI analysis pending
6.11%
  • enhancesoft osticket
CVE-2020-16193
osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.

osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.

NVD description · AI analysis pending
5.4<1%
  • enhancesoft osticket
CVE-2020-14012
scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description.

scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent.

NVD description · AI analysis pending
5.4<1% PoC
  • enhancesoft osticket
CVE-2020-12629
include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.

include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.

NVD description · AI analysis pending
5.42% PoC
  • enhancesoft osticket
CVE-2019-14749
+2 in the same advisory: …14750 …14748
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1.

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user input in the Name and Internal Notes fields in the Users tab, and the Issue Summary field in the tickets tab. This allows other agents to download data in a .csv file format or .xls file format. This is used as input for spreadsheet applications such as Excel and OpenOffice Calc, resulting in a situation where cells in the spreadsheets can contain input from an untrusted source. As a result, the end user who is accessing the exported spreadsheet can be affected.

NVD description · AI analysis pending
8.8
group max
10%
  • enhancesoft osticket
CVE-2019-13397
Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file ext

Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.

NVD description · AI analysis pending
6.11%
  • enhancesoft osticket
CVE-2019-11537
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user

In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can appear in an error message. The XSS can lead to local file inclusion.

NVD description · AI analysis pending
6.15% PoC ×3
  • enhancesoft osticket
CVE-2018-7195
+4 in the same advisory: …7196 …7193 …7192 …7194
Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access

Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access and guessing a 6-digit number.

NVD description · AI analysis pending
8.1
group max
<1% PoC
  • enhancesoft osticket