CVEs we hold for Otrs
Records whose assigning authority named Otrs as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-48210Possible information disclosure via External InterfaceOTRS CVE-2026-48209Reflected XSS in authenticated agent contextOTRS AG ((OTRS)) Community Edition CVE-2026-48208Denial-of-Service via SVG Rendering in TicketOTRS AG ((OTRS)) Community Edition CVE-2026-48191Wrong Permission Handling in Document Search Article Meta FiltersOTRS CVE-2026-48190Incorrect handling of permissions in External Interface Config Item List moduleOTRS CVE-2026-48188SQL Injection via MySQL Quote MethodOTRS AG ((OTRS)) Community Edition CVE-2026-48187Email with special content can lead to DoSOTRS AG ((OTRS)) Community Edition CVE-2025-24389SMTP Password will be shown in cleartext on some SMTP errorsOTRS AG ((OTRS)) Community Edition CVE-2025-24388Unsafe handling of AJAX callsOTRS AG ((OTRS)) Community Edition CVE-2024-43446Improper check of permissions in Generic InterfaceOTRS AG ((OTRS)) Community Edition CVE-2024-43445Missing X-Content-Type-Options: nosniff Header Allows MIME Type SniffingOTRS AG ((OTRS)) Community Edition CVE-2024-43444Passwords are written to Admin Log ModuleOTRS AG ((OTRS)) Community Edition CVE-2024-43443Stored XSS in process managementOTRS AG ((OTRS)) Community Edition CVE-2024-43442Stored XSS in System ConfigurationOTRS AG ((OTRS)) Community Edition CVE-2024-23794Agents are able to lock the ticket without the "Owner" permissionOTRS CVE-2024-23793Upload of files outside application directoryOTRS AG ((OTRS)) Community Edition CVE-2024-23791Unnecessary data is written to log if issues during indexing occursOTRS CVE-2023-5422SSL Certificates are not checked for E-Mail HandlingOTRS AG ((OTRS)) Community Edition CVE-2023-5421Possible XSS execution in customer informationOTRS AG ((OTRS)) Community Edition CVE-2023-38060Host header injection by attachments in web serviceOTRS AG ((OTRS)) Community Edition CVE-2023-38059External pictures can be loaded even if not allowed by configurationOTRS AG ((OTRS)) Community Edition CVE-2023-38057XSS stored in survey answersOTRS AG ((OTRS)) Community Edition CVE-2023-38056Code execution via System ConfigurationOTRS AG ((OTRS)) Community Edition CVE-2023-2534Information disclouse and DoS via websocket push eventsOTRS CVE-2023-1250Code execution through ACL creationOTRS AG ((OTRS)) Community Edition CVE-2023-1248Possible XSS in Ticket ActionsOTRS AG ((OTRS)) Community Edition CVE-2022-4427SQL Injection via OTRS Search APIOTRS AG ((OTRS)) Community Edition CVE-2022-39052DoS attack using emailOTRS AG ((OTRS)) Community Edition CVE-2022-39051Perl Code execution in Template ToolkitOTRS AG ((OTRS)) Community Edition CVE-2022-39050Possible XSS stored in customer informationOTRS AG ((OTRS)) Community Edition CVE-2022-39049Possible XSS in Admin InterfaceOTRS AG ((OTRS)) Community Edition CVE-2022-32741Information disclosure in Request New Password featureOTRS CVE-2022-32739OTRS version number is always in the exported ICS filesOTRS AG OTRSCalendarResourcePlanning CVE-2022-1004Information disclosure in the External InterfaceOTRS CVE-2022-0474Disclosure of mail addressesOTRS AG OTRSCustomContactFields CVE-2022-0473Dynamic field error message is vulnerable to XSSOTRS CVE-2021-36100Authenticated remote code executionOTRS AG ((OTRS)) Community Edition CVE-2021-36097Agents are able to lock the ticket without the "Owner" permissionOTRS CVE-2021-36096Support Bundle includes S/Mime and PGP secret or PINOTRS CVE-2021-36095User enumeration issue using "lost password" featureOTRS CVE-2021-21442XSS vulnerability in Time AccountingOTRS AG Time Accounting CVE-2021-21439Possible DoS attack using a special crafted URL in email bodyOTRS CVE-2021-21437Config Items are shown to users without permissionOTRS AG ITSMConfigurationManagement CVE-2021-21436Agent is able to link customer's Config Items without permissionOTRS AG OTRSCIsInCustomerFrontend CVE-2020-1779Dynamic templates reveal sensitive data when OTRS tags are usedOTRS AG OTRSTicketForms CVE-2020-1776Invalidating or changing user does not invalidate sessionOTRS CVE-2020-1767Possible to send drafted messages as wrong agentOTRS 81 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.