Enhancesoft
Enhancesoft Osticket: vulnerabilidades y CVE
Enhancesoft Osticket tiene 45 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE45
Últimos 12 meses2
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-26895 | Media (5.3) | 0.41% | — | 2 abr 2026 | User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform. |
| CVE-2026-22200 | Alta (8.7) | 74% | — | 12 ene 2026 | Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing… |
| CVE-2025-26241 | Media (6.5) | 0.30% | — | 5 may 2025 | A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters… |
| CVE-2023-46967 | Media (6.1) | 0.44% | — | 20 feb 2024 | Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket. |
| CVE-2023-27149 | Media (4.8) | 0.35% | — | 23 oct 2023 | A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a… |
| CVE-2023-27148 | Media (4.8) | 0.35% | — | 23 oct 2023 | A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Role Name parameter. |
| CVE-2021-45811 | Media (6.5) | 2.5% | — | 8 sept 2023 | A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters… |
| CVE-2023-30082 | Alta (7.5) | 1.00% | — | 14 jun 2023 | A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop… |
| CVE-2022-31888 | Alta (8.8) | 1.2% | — | 5 abr 2023 | Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2. |
| CVE-2023-1320 | Media (6.1) | 0.62% | — | 10 mar 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6. |
| CVE-2023-1319 | Media (4.8) | 0.47% | — | 10 mar 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6. |
| CVE-2023-1318 | Media (5.4) | 1.0% | — | 10 mar 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository osticket/osticket prior to v1.16.6. |
| CVE-2023-1317 | Media (5.4) | 1.0% | — | 10 mar 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6. |
| CVE-2023-1316 | Media (5.4) | 0.51% | — | 10 mar 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6. |
| CVE-2023-1315 | Media (5.4) | 1.1% | — | 10 mar 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6. |
| CVE-2022-4271 | Media (5.4) | 0.72% | — | 2 dic 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4. |
| CVE-2022-32074 | Media (5.4) | 1.5% | — | 13 jul 2022 | A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web… |
| CVE-2021-42235 | Crítica (9.8) | 1.0% | — | 4 may 2022 | SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality. |
| CVE-2020-22609 | Media (6.1) | 0.69% | — | 28 jun 2021 | Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php. |
| CVE-2020-22608 | Media (6.1) | 0.67% | — | 28 jun 2021 | Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php. |
| CVE-2020-24881 | Crítica (9.8) | 73% | — | 2 nov 2020 | SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. |
| CVE-2020-24917 | Media (6.1) | 1.2% | — | 30 ago 2020 | osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php. |
| CVE-2020-16193 | Media (5.4) | 0.59% | — | 26 ago 2020 | osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call. |
| CVE-2020-14012 | Media (5.4) | 0.51% | — | 10 jun 2020 | scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent. |
| CVE-2020-12629 | Media (5.4) | 1.5% | — | 4 may 2020 | include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name. |
| CVE-2019-14750 | Media (6.1) | 11% | — | 7 ago 2019 | An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the… |
| CVE-2019-14749 | Alta (8.8) | 9.6% | — | 7 ago 2019 | An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or… |
| CVE-2019-14748 | Media (5.4) | 2.7% | — | 7 ago 2019 | An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no)… |
| CVE-2019-13397 | Media (6.1) | 1.1% | — | 9 jul 2019 | Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket. |
| CVE-2019-11537 | Media (6.1) | 4.6% | — | 25 abr 2019 | In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.