bestpractical has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was July 2026 with 4. The median CVSS is 6.1 (medium), with 1 rated critical. The most common weakness class is CWE-79 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.1
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-44231Critical· 9.1RT is an open source, enterprise-grade issue and ticket tracking system50CVE-2026-44230Medium· 6.1RT is an open source, enterprise-grade issue and ticket tracking system34CVE-2026-44227Medium· 6.1RT is an open source, enterprise-grade issue and ticket tracking system34CVE-2026-44228Medium· 5.4RT is an open source, enterprise-grade issue and ticket tracking system30
bestpractical vulnerabilities
CVEs affecting bestpractical, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-44231Critical· 9.1RT is an open source, enterprise-grade issue and ticket tracking system
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged…
CVE-2026-44230Medium· 6.1RT is an open source, enterprise-grade issue and ticket tracking system
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an att…
CVE-2026-44228Medium· 5.4RT is an open source, enterprise-grade issue and ticket tracking system
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML esca…
CVE-2026-44227Medium· 6.1RT is an open source, enterprise-grade issue and ticket tracking system
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit …