ZeroHour

Vulnerabilities

90 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-34723
Zammad is a web based open source helpdesk/customer support system.

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote attackers were able to access the getting started endpoint to get access to sensitive internal entity data, even after the system setup was completed. This vulnerability is fixed in 7.0.1 and 6.5.4.

NVD description · AI analysis pending
8.7
group max
<1%
  • zammad zammad
CVE-2025-32359
+3 in the same advisory: …32360 …32357 …32358
In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security.

In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was enforced in Zammad only on the front end level, and not when using the API directly.

NVD description · AI analysis pending
8.8
group max
<1%
  • zammad zammad
CVE-2024-55578
Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.

Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.

NVD description · AI analysis pending
4.3<1%
  • zammad zammad
CVE-2024-36078
In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions.

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).

NVD description · AI analysis pending
6.7<1%
  • zammad zammad
CVE-2024-33668
+2 in the same advisory: …33666 …33667
An issue was discovered in Zammad before 6.3.0.

An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.

NVD description · AI analysis pending
9.1
group max
<1%
  • zammad zammad
CVE-2023-50455
+4 in the same advisory: …50454 …50453 …50456 …50457
An issue was discovered in Zammad before 6.2.0.

An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many requests for a known address to cause Denial Of Service (generation of many emails, which would also spam the victim).

NVD description · AI analysis pending
7.5
group max
<1%
  • zammad zammad
CVE-2023-31597
An issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address and manipulate the data of the generated user.

An issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address and manipulate the data of the generated user. Attackers are also able to gain unauthorized access to existing tickets.

NVD description · AI analysis pending
6.5<1%
  • zammad zammad
CVE-2023-29868
+1 in the same advisory: …29867
Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control.

Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.

NVD description · AI analysis pending
6.51%
  • zammad zammad
CVE-2022-48021
+2 in the same advisory: …48022 …48023
A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.

A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.

NVD description · AI analysis pending
9.8
group max
<1%
  • zammad zammad
CVE-2022-40816
+1 in the same advisory: …40817
Zammad 5.2.1 is vulnerable to Incorrect Access Control.

Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that customer users are not able to see personal information of other users. This logic was not effective when used through a web socket connection, so that a logged-in attacker would be able to fetch personal data of other users by querying the Zammad API. This issue is fixed in , 5.2.2.

NVD description · AI analysis pending
6.5
group max
<1%
  • zammad zammad
CVE-2022-35490
+3 in the same advisory: …35488 …35487 …35489
Zammad 5.2.0 is vulnerable to privilege escalation.

Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling them to send more than the configured amount of requests before the user invalidation takes place.

NVD description · AI analysis pending
9.8
group max
<1%
  • zammad zammad
CVE-2022-27332
+3 in the same advisory: …29701 …29700 …27331
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication.

An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).

NVD description · AI analysis pending
9.1
group max
1%
  • zammad zammad
CVE-2021-43145
+1 in the same advisory: …44886
With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.

With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.

NVD description · AI analysis pending
8.1
group max
<1%
  • zammad zammad
CVE-2021-42137
An issue was discovered in Zammad before 5.0.1.

An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of tickets that shows title, state, etc.

NVD description · AI analysis pending
5.3<1%
  • zammad zammad
CVE-2021-42090
An issue was discovered in Zammad before 4.1.1.

An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.

NVD description · AI analysis pending
9.8
group max
2%
  • zammad zammad