VendorsEnhancesoftosticketany version
Vulnerabilities

Enhancesoft osTicket any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

38CVEs
CVE-2020-24881
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
Published 2020-11-02 · Modified
9.81 PoCEPSS 0.734
CVE-2021-42235
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.
Published 2022-05-04 · Modified
9.8EPSS 0.010
CVE-2019-14749
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user input in the Name and Internal Notes fields in the Users tab, and the Issue Summary field in the tickets tab. This allows other agents to download data in a .csv file format or .xls file format. This is used as input for spreadsheet applications such as Excel and OpenOffice Calc, resulting in a situation where cells in the spreadsheets can contain input from an untrusted source. As a result, the end user who is accessing the exported spreadsheet can be affected.
Published 2019-08-07 · Modified
8.81 PoCEPSS 0.096
CVE-2022-31888
Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.
Published 2023-04-05 · Modified
8.8EPSS 0.012
CVE-2026-22200
osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read
Published 2026-01-12 · Analyzed
8.7EPSS 0.739
CVE-2018-7195
Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access and guessing a 6-digit number.
Published 2018-03-27 · Modified
8.1EPSS 0.010
CVE-2022-4271
Cross-site Scripting (XSS) - Reflected in osticket/osticket
Published 2022-12-02 · Modified
8.0EPSS 0.007
CVE-2009-2361
SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.
Published 2009-07-08 · Modified
7.51 PoCEPSS 0.052
CVE-2010-0605
SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.
Published 2010-02-11 · Modified
7.51 PoCEPSS 0.030
CVE-2005-1439
Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file parameter.
Published 2005-05-03 · Modified
7.5EPSS 0.017
CVE-2006-5407
PHP remote file inclusion vulnerability in open_form.php in osTicket allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.
Published 2006-10-19 · Modified
7.5EPSS 0.015
CVE-2023-1320
Cross-site Scripting (XSS) - Stored in osticket/osticket
Published 2023-03-10 · Modified
7.1EPSS 0.006
CVE-2021-45811
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
Published 2023-09-08 · Modified
6.5EPSS 0.025
CVE-2025-26241
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
Published 2025-05-05 · Analyzed
6.5EPSS 0.003
CVE-2019-14750
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.
Published 2019-08-07 · Modified
6.11 PoCEPSS 0.109
CVE-2019-11537
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can appear in an error message. The XSS can lead to local file inclusion.
Published 2019-04-25 · Modified
6.11 PoCEPSS 0.046
CVE-2018-7193
Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" parameter.
Published 2018-03-27 · Modified
6.1EPSS 0.024
CVE-2018-7196
Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" parameter.
Published 2018-03-27 · Modified
6.1EPSS 0.024
CVE-2018-7192
Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "message" parameter.
Published 2018-03-27 · Modified
6.1EPSS 0.020
CVE-2020-24917
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.
Published 2020-08-30 · Modified
6.1EPSS 0.012
CVE-2020-22609
Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.
Published 2021-06-28 · Modified
6.1EPSS 0.007
CVE-2020-22608
Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php.
Published 2021-06-28 · Modified
6.1EPSS 0.007
CVE-2023-46967
Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.
Published 2024-02-20 · Analyzed
6.1EPSS 0.004
CVE-2019-14748
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implemented for file content checks; also, the output is not handled properly, causing persistent XSS that leads to cookie stealing or malicious actions. For example, a non-agent user can upload a .html file, and Content-Disposition will be set to inline instead of attachment.
Published 2019-08-07 · Modified
5.41 PoCEPSS 0.027
CVE-2020-12629
include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.
Published 2020-05-04 · Modified
5.4EPSS 0.015
CVE-2022-32074
A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.
Published 2022-07-13 · Modified
5.4EPSS 0.015
CVE-2023-1315
Cross-site Scripting (XSS) - Reflected in osticket/osticket
Published 2023-03-10 · Modified
5.4EPSS 0.011
CVE-2023-1317
Cross-site Scripting (XSS) - Reflected in osticket/osticket
Published 2023-03-10 · Modified
5.4EPSS 0.010
CVE-2023-1318
Cross-site Scripting (XSS) - Generic in osticket/osticket
Published 2023-03-10 · Modified
5.4EPSS 0.010
CVE-2020-16193
osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.
Published 2020-08-26 · Modified
5.4EPSS 0.006
CVE-2023-1316
Cross-site Scripting (XSS) - Stored in osticket/osticket
Published 2023-03-10 · Modified
5.4EPSS 0.005
CVE-2026-26895
User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.
Published 2026-04-02 · Modified
5.3EPSS 0.004
CVE-2018-7194
Integer format vulnerability in the ticket number generator in Enhancesoft osTicket before 1.10.2 allows remote attackers to cause a denial-of-service (preventing the creation of new tickets) via a large number of digits in the ticket number format setting.
Published 2018-03-27 · Modified
4.9EPSS 0.013
CVE-2023-1319
Cross-site Scripting (XSS) - Stored in osticket/osticket
Published 2023-03-10 · Modified
4.8EPSS 0.005
CVE-2014-4744
Multiple cross-site scripting (XSS) vulnerabilities in osTicket before 1.9.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Phone Number field to open.php or (2) Phone number field, (3) passwd1 field, (4) passwd2 field, or (5) do parameter to account.php.
Published 2014-07-09 · Modified
4.3EPSS 0.019
CVE-2015-1176
Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter in a search action.
Published 2015-01-23 · Modified
4.3EPSS 0.019
CVE-2015-1347
Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Published 2015-01-23 · Modified
4.3EPSS 0.014
CVE-2010-0606
Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/admin.php.
Published 2010-02-11 · Modified
3.5EPSS 0.009