VulnSea

enhancesoft has 20 CVEs on record between 2010 and 2025. The median CVSS is 6.1 (medium), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-79 (13).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
0 prev 0

Products

  • osticket 20
20
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

enhancesoft vulnerabilities

CVEs affecting enhancesoft, newest first. Open any entry for full detail, references, and exploit status.

20 CVEsRSS

CVE-2025-26241Medium· 6.5
1y ago

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

Sunlitenhancesoft · osticketEPSS 0.29%via NVD
CVE-2022-32074Medium· 5.4PoC
4y ago

A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web scripts or HTML vi…

A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web scripts or HTML vi…

Twilightenhancesoft · osticketEPSS 1.5%via NVD
CVE-2020-24881Critical· 9.8PoC
5y ago

SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

Abyssalenhancesoft · osticketEPSS 73%via NVD
CVE-2020-24917Medium· 6.1
6y ago

osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.

osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.

Sunlitenhancesoft · osticketEPSS 1.2%via NVD
CVE-2020-16193Medium· 5.4
6y ago

osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.

osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.

Sunlitenhancesoft · osticketEPSS 0.59%via NVD
CVE-2019-14750Medium· 6.1PoC
7y ago

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The inse…

Twilightenhancesoft · osticketEPSS 13%via NVD
CVE-2019-14749High· 8.8PoC
7y ago

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user inp…

Midnightenhancesoft · osticketEPSS 7.7%via NVD
CVE-2019-14748Medium· 5.4PoC
7y ago

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implement…

Twilightenhancesoft · osticketEPSS 3.6%via NVD
CVE-2019-11537Medium· 6.1PoC
7y ago

In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can a…

In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can a…

Twilightenhancesoft · osticketEPSS 4.7%via NVD
CVE-2018-7196Medium· 6.1PoC
8y ago

Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" parameter.

Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" parameter.

Twilightenhancesoft · osticketEPSS 3.1%via NVD
CVE-2018-7195High· 8.1
8y ago

Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access and guessing a 6-digit number.

Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access and guessing a 6-digit number.

Twilightenhancesoft · osticketEPSS 1.0%via NVD
CVE-2018-7194Medium· 4.9
8y ago

Integer format vulnerability in the ticket number generator in Enhancesoft osTicket before 1.10.2 allows remote attackers to cause a denial-of-service (preventing the creation of new tickets) via a large number of digits in the ticket nu…

Integer format vulnerability in the ticket number generator in Enhancesoft osTicket before 1.10.2 allows remote attackers to cause a denial-of-service (preventing the creation of new tickets) via a large number of digits in the ticket nu…

Sunlitenhancesoft · osticketEPSS 1.2%via NVD
CVE-2018-7193Medium· 6.1PoC
8y ago

Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" parameter.

Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" parameter.

Twilightenhancesoft · osticketEPSS 3.1%via NVD
CVE-2018-7192Medium· 6.1PoC
8y ago

Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "message" parameter.

Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "message" parameter.

Twilightenhancesoft · osticketEPSS 2.7%via NVD
CVE-2015-1347Medium· 4.3
11y ago

Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

Sunlitenhancesoft · osticketEPSS 1.4%via NVD
CVE-2015-1176Medium· 4.3
11y ago

Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter in a search action.

Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter in a search action.

Sunlitenhancesoft · osticketEPSS 1.9%via NVD
CVE-2014-4744Medium· 4.3
12y ago

Multiple cross-site scripting (XSS) vulnerabilities in osTicket before 1.9.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Phone Number field to open.php or (2) Phone number field, (3) passwd1 field, (4) passw…

Multiple cross-site scripting (XSS) vulnerabilities in osTicket before 1.9.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Phone Number field to open.php or (2) Phone number field, (3) passwd1 field, (4) passw…

Sunlitenhancesoft · osticketEPSS 1.9%via NVD
CVE-2010-4634Medium· 5.0
15y ago

Directory traversal vulnerability in osTicket 1.6 allows remote attackers to read arbitrary files via a .

Directory traversal vulnerability in osTicket 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to module.php, a different vector than CVE-2005-1439. NOTE: this issue has been disputed by a rel…

Sunlitenhancesoft · osticketEPSS 2.5%via NVD
CVE-2010-0606Low· 3.5
16y ago

Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/…

Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/…

Sunlitenhancesoft · osticketEPSS 0.88%via NVD
CVE-2010-0605High· 7.5PoC
16y ago

SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.

SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.

Midnightenhancesoft · osticketEPSS 3.0%via NVD
enhancesoft vulnerabilities (CVEs) · VulnSea