vciy

CVEs we hold for Otrs

Records whose assigning authority named Otrs as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-6060Possible DoS via SQL BoxOTRS
CVE-2026-48210Possible information disclosure via External InterfaceOTRS
CVE-2026-48209Reflected XSS in authenticated agent contextOTRS AG ((OTRS)) Community Edition
CVE-2026-48208Denial-of-Service via SVG Rendering in TicketOTRS AG ((OTRS)) Community Edition
CVE-2026-48191Wrong Permission Handling in Document Search Article Meta FiltersOTRS
CVE-2026-48190Incorrect handling of permissions in External Interface Config Item List moduleOTRS
CVE-2026-48189Bypass DedicatedAgentToCustomerGroups SettingOTRS
CVE-2026-48188SQL Injection via MySQL Quote MethodOTRS AG ((OTRS)) Community Edition
CVE-2026-48187Email with special content can lead to DoSOTRS AG ((OTRS)) Community Edition
CVE-2025-24391Possible user enumerationOTRS
CVE-2025-24390Missing Cookie FlagsOTRS
CVE-2025-24389SMTP Password will be shown in cleartext on some SMTP errorsOTRS AG ((OTRS)) Community Edition
CVE-2025-24388Unsafe handling of AJAX callsOTRS AG ((OTRS)) Community Edition
CVE-2025-24387Missing CSRF protectionOTRS
CVE-2024-6540Information exlosure in external interfaceOTRS
CVE-2024-43446Improper check of permissions in Generic InterfaceOTRS AG ((OTRS)) Community Edition
CVE-2024-43445Missing X-Content-Type-Options: nosniff Header Allows MIME Type SniffingOTRS AG ((OTRS)) Community Edition
CVE-2024-43444Passwords are written to Admin Log ModuleOTRS AG ((OTRS)) Community Edition
CVE-2024-43443Stored XSS in process managementOTRS AG ((OTRS)) Community Edition
CVE-2024-43442Stored XSS in System ConfigurationOTRS AG ((OTRS)) Community Edition
CVE-2024-23794Agents are able to lock the ticket without the "Owner" permissionOTRS
CVE-2024-23793Upload of files outside application directoryOTRS AG ((OTRS)) Community Edition
CVE-2024-23792Insufficient access controlOTRS
CVE-2024-23791Unnecessary data is written to log if issues during indexing occursOTRS
CVE-2024-23790Missing file type check in avatar picture uploadOTRS
CVE-2023-6254Password is send back to clientOTRS
CVE-2023-5422SSL Certificates are not checked for E-Mail HandlingOTRS AG ((OTRS)) Community Edition
CVE-2023-5421Possible XSS execution in customer informationOTRS AG ((OTRS)) Community Edition
CVE-2023-38060Host header injection by attachments in web serviceOTRS AG ((OTRS)) Community Edition
CVE-2023-38059External pictures can be loaded even if not allowed by configurationOTRS AG ((OTRS)) Community Edition
CVE-2023-38058Tickets can be moved without permissionsOTRS
CVE-2023-38057XSS stored in survey answersOTRS AG ((OTRS)) Community Edition
CVE-2023-38056Code execution via System ConfigurationOTRS AG ((OTRS)) Community Edition
CVE-2023-2534Information disclouse and DoS via websocket push eventsOTRS
CVE-2023-1250Code execution through ACL creationOTRS AG ((OTRS)) Community Edition
CVE-2023-1248Possible XSS in Ticket ActionsOTRS AG ((OTRS)) Community Edition
CVE-2022-4427SQL Injection via OTRS Search APIOTRS AG ((OTRS)) Community Edition
CVE-2022-39052DoS attack using emailOTRS AG ((OTRS)) Community Edition
CVE-2022-39051Perl Code execution in Template ToolkitOTRS AG ((OTRS)) Community Edition
CVE-2022-39050Possible XSS stored in customer informationOTRS AG ((OTRS)) Community Edition
CVE-2022-39049Possible XSS in Admin InterfaceOTRS AG ((OTRS)) Community Edition
CVE-2022-32741Information disclosure in Request New Password featureOTRS
CVE-2022-32740Information disclosure in the External InterfaceOTRS
CVE-2022-32739OTRS version number is always in the exported ICS filesOTRS AG OTRSCalendarResourcePlanning
CVE-2022-1004Information disclosure in the External InterfaceOTRS
CVE-2022-0475Possible XSS attack via translationOTRS
CVE-2022-0474Disclosure of mail addressesOTRS AG OTRSCustomContactFields
CVE-2022-0473Dynamic field error message is vulnerable to XSSOTRS
CVE-2021-36100Authenticated remote code executionOTRS AG ((OTRS)) Community Edition
CVE-2021-36097Agents are able to lock the ticket without the "Owner" permissionOTRS
CVE-2021-36096Support Bundle includes S/Mime and PGP secret or PINOTRS
CVE-2021-36095User enumeration issue using "lost password" featureOTRS
CVE-2021-36094XSS attack in appointment edit popup screenOTRS
CVE-2021-36093DoS attack using PostMaster filtersOTRS
CVE-2021-36092XSS attack using special link in emailOTRS
CVE-2021-36091Unautorized access to the calendar appointmentsOTRS
CVE-2021-21443Unautorized listing of the customer user emailsOTRS
CVE-2021-21442XSS vulnerability in Time AccountingOTRS AG Time Accounting
CVE-2021-21441XSS in the ticket overview screensOTRS
CVE-2021-21440Support Bundle includes S/Mime and PGP keysOTRS
CVE-2021-21439Possible DoS attack using a special crafted URL in email bodyOTRS
CVE-2021-21438FAQ articles are shown to users without permissionOTRS
CVE-2021-21437Config Items are shown to users without permissionOTRS AG ITSMConfigurationManagement
CVE-2021-21436Agent is able to link customer's Config Items without permissionOTRS AG OTRSCIsInCustomerFrontend
CVE-2021-21435Information exposure in PDF exportOTRS
CVE-2021-21434XSS in Survey ModuleOTRS AG Survey
CVE-2020-1779Dynamic templates reveal sensitive data when OTRS tags are usedOTRS AG OTRSTicketForms
CVE-2020-1778Bypassing user account validationOTRS
CVE-2020-1777Agent names disclosed in chat featureOTRS
CVE-2020-1776Invalidating or changing user does not invalidate sessionOTRS
CVE-2020-1775Information disclosure in external interfaceOTRS
CVE-2020-1774Information disclosureOTRS
CVE-2020-1773Session / Password / Password token leakOTRS
CVE-2020-1772Information DisclosureOTRS
CVE-2020-1771Possible XSS in Customer user address bookOTRS
CVE-2020-1770Information disclosure in support bundle filesOTRS
CVE-2020-1769Autocomplete in the form login screensOTRS
CVE-2020-1768External Interface does not invalidate sessionOTRS
CVE-2020-1767Possible to send drafted messages as wrong agentOTRS
CVE-2020-1766Improper handling of uploaded inline imagesOTRS
CVE-2020-1765Spoofing of From field in several screensOTRS

81 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.