Vulnerabilities (CVE)

Filtered by vendor Enhancesoft Subscribe
Total 47 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-31888 1 Enhancesoft 1 Osticket 2026-06-17 N/A 8.8 HIGH
Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.
CVE-2021-42235 1 Enhancesoft 1 Osticket 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.
CVE-2020-22609 1 Enhancesoft 1 Osticket 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.
CVE-2020-22608 1 Enhancesoft 1 Osticket 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php.
CVE-2020-14012 1 Enhancesoft 1 Osticket 2026-06-17 3.5 LOW 5.4 MEDIUM
scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent.
CVE-2020-12629 1 Enhancesoft 1 Osticket 2026-06-17 3.5 LOW 5.4 MEDIUM
include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.
CVE-2019-13397 1 Enhancesoft 1 Osticket 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.