Enhancesoft
Enhancesoft Osticket: vulnerabilities and CVEs
Enhancesoft Osticket has 45 published vulnerabilities, 2 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs45
Last 12 months2
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26895 | Medium (5.3) | 0.41% | — | Apr 2, 2026 | User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform. |
| CVE-2026-22200 | High (8.7) | 74% | — | Jan 12, 2026 | Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing… |
| CVE-2025-26241 | Medium (6.5) | 0.30% | — | May 5, 2025 | A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters… |
| CVE-2023-46967 | Medium (6.1) | 0.44% | — | Feb 20, 2024 | Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket. |
| CVE-2023-27149 | Medium (4.8) | 0.35% | — | Oct 23, 2023 | A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a… |
| CVE-2023-27148 | Medium (4.8) | 0.35% | — | Oct 23, 2023 | A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Role Name parameter. |
| CVE-2021-45811 | Medium (6.5) | 2.5% | — | Sep 8, 2023 | A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters… |
| CVE-2023-30082 | High (7.5) | 1.00% | — | Jun 14, 2023 | A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop… |
| CVE-2022-31888 | High (8.8) | 1.2% | — | Apr 5, 2023 | Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2. |
| CVE-2023-1320 | Medium (6.1) | 0.62% | — | Mar 10, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6. |
| CVE-2023-1319 | Medium (4.8) | 0.47% | — | Mar 10, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6. |
| CVE-2023-1318 | Medium (5.4) | 1.0% | — | Mar 10, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository osticket/osticket prior to v1.16.6. |
| CVE-2023-1317 | Medium (5.4) | 1.0% | — | Mar 10, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6. |
| CVE-2023-1316 | Medium (5.4) | 0.51% | — | Mar 10, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6. |
| CVE-2023-1315 | Medium (5.4) | 1.1% | — | Mar 10, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6. |
| CVE-2022-4271 | Medium (5.4) | 0.72% | — | Dec 2, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4. |
| CVE-2022-32074 | Medium (5.4) | 1.5% | — | Jul 13, 2022 | A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web… |
| CVE-2021-42235 | Critical (9.8) | 1.0% | — | May 4, 2022 | SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality. |
| CVE-2020-22609 | Medium (6.1) | 0.69% | — | Jun 28, 2021 | Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php. |
| CVE-2020-22608 | Medium (6.1) | 0.67% | — | Jun 28, 2021 | Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php. |
| CVE-2020-24881 | Critical (9.8) | 73% | — | Nov 2, 2020 | SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. |
| CVE-2020-24917 | Medium (6.1) | 1.2% | — | Aug 30, 2020 | osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php. |
| CVE-2020-16193 | Medium (5.4) | 0.59% | — | Aug 26, 2020 | osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call. |
| CVE-2020-14012 | Medium (5.4) | 0.51% | — | Jun 10, 2020 | scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent. |
| CVE-2020-12629 | Medium (5.4) | 1.5% | — | May 4, 2020 | include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name. |
| CVE-2019-14750 | Medium (6.1) | 11% | — | Aug 7, 2019 | An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the… |
| CVE-2019-14749 | High (8.8) | 9.6% | — | Aug 7, 2019 | An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or… |
| CVE-2019-14748 | Medium (5.4) | 2.7% | — | Aug 7, 2019 | An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no)… |
| CVE-2019-13397 | Medium (6.1) | 1.1% | — | Jul 9, 2019 | Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket. |
| CVE-2019-11537 | Medium (6.1) | 4.6% | — | Apr 25, 2019 | In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.