Vulnerabilities (CVE)

Filtered by vendor Enhancesoft Subscribe
Filtered by product Osticket
Total 45 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-26895 1 Enhancesoft 1 Osticket 2026-07-24 N/A 5.3 MEDIUM
User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.
CVE-2026-22200 1 Enhancesoft 1 Osticket 2026-07-14 N/A 7.5 HIGH
Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled.
CVE-2018-7194 1 Enhancesoft 1 Osticket 2026-07-10 4.0 MEDIUM 4.9 MEDIUM
Integer format vulnerability in the ticket number generator in Enhancesoft osTicket before 1.10.2 allows remote attackers to cause a denial-of-service (preventing the creation of new tickets) via a large number of digits in the ticket number format setting.
CVE-2018-7196 1 Enhancesoft 1 Osticket 2026-07-10 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" parameter.
CVE-2005-1439 1 Enhancesoft 1 Osticket 2026-07-10 7.5 HIGH N/A
Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file parameter.
CVE-2006-5407 1 Enhancesoft 1 Osticket 2026-07-10 7.5 HIGH N/A
PHP remote file inclusion vulnerability in open_form.php in osTicket allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.
CVE-2018-7192 1 Enhancesoft 1 Osticket 2026-07-10 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "message" parameter.
CVE-2020-16193 1 Enhancesoft 1 Osticket 2026-07-10 3.5 LOW 5.4 MEDIUM
osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.
CVE-2015-1176 1 Enhancesoft 1 Osticket 2026-07-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter in a search action.
CVE-2020-24917 1 Enhancesoft 1 Osticket 2026-07-10 4.3 MEDIUM 6.1 MEDIUM
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.
CVE-2018-7195 1 Enhancesoft 1 Osticket 2026-07-10 4.3 MEDIUM 8.1 HIGH
Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access and guessing a 6-digit number.
CVE-2015-1347 1 Enhancesoft 1 Osticket 2026-07-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
CVE-2019-11537 1 Enhancesoft 1 Osticket 2026-07-10 4.3 MEDIUM 6.1 MEDIUM
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can appear in an error message. The XSS can lead to local file inclusion.
CVE-2014-4744 1 Enhancesoft 1 Osticket 2026-07-10 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in osTicket before 1.9.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Phone Number field to open.php or (2) Phone number field, (3) passwd1 field, (4) passwd2 field, or (5) do parameter to account.php.
CVE-2010-0605 2 Enhancesoft, Osticket 2 Osticket, Osticket 2026-07-10 7.5 HIGH N/A
SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.
CVE-2010-4634 1 Enhancesoft 1 Osticket 2026-07-10 5.0 MEDIUM N/A
Directory traversal vulnerability in osTicket 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to module.php, a different vector than CVE-2005-1439. NOTE: this issue has been disputed by a reliable third party
CVE-2009-2361 1 Enhancesoft 1 Osticket 2026-07-10 7.5 HIGH N/A
SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.
CVE-2025-26241 1 Enhancesoft 1 Osticket 2026-07-10 N/A 6.5 MEDIUM
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
CVE-2018-7193 1 Enhancesoft 1 Osticket 2026-07-10 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" parameter.
CVE-2020-24881 1 Enhancesoft 1 Osticket 2026-07-10 7.5 HIGH 9.8 CRITICAL
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.