OTRS AG

First CVE: Jan 10, 2020Active for: 7 years
82
CVEs Published
More CVEs Published than 67% of tracked CNAs
11.7
Avg CVEs / Year
More Avg CVEs / Year than 58% of tracked CNAs
5.8
Avg CVSS Score
Higher Avg CVSS Score than 7% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by OTRS AG as a CNA, 86.6% affect products that OTRS AG develops as a vendor.

86.6%
13.4%
Self-reported: 71Third-party: 11

Of all the CVEs published that affect products developed by OTRS AG, 44.7% are self-published by OTRS AG as a CNA.

44.7%
55.3%
Self-published: 71Published by other CNAs: 88

Trends Over Time

The number and severity of CVEs published by OTRS AG over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2020
6 years ago
Most Recent CVE
Jun 1, 2026
53 days ago

Top CVEs

All CVEs published by OTRS AG as a CNA, regardless of affected vendor or product.

82 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication b
Jun 1, 20269.139NONO
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This issue affects OTRS: from 7.0.1 bef
Dec 19, 20229.831NONO
An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform reflected cross-site scripting
Jun 1, 20267.130NONO
Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7
Jan 29, 20249.829NONO
An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email
Jun 1, 20266.528NONO
Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package
Sep 5, 20228.828NONO
Specially crafted string in OTRS system configuration can allow the execution of any system command.
Mar 21, 20228.828NONO
An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disablin
May 31, 20265.727NONO
An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups. Please note that the feature
Jun 1, 20265.726NONO
An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the abortion of the webserver.This
Jun 1, 20265.726NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA82 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local2 (2.4%)
Network80 (97.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low78 (95.1%)
High4 (4.9%)
Unknown0 (0.0%)
User Interaction
None52 (63.4%)
Unknown0 (0.0%)
Required30 (36.6%)
Privileges Required
Low38 (46.3%)
High13 (15.9%)
None31 (37.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (82 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by OTRS AG as a CNA.

Media Mentions

Media articles that mention a CVE ID published by OTRS AG as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs