Best Practical Solutions maintains Request Tracker, a widely deployed open-source ticketing and issue-management platform used across organizations to coordinate workflow and track requests. The durable vulnerability signal centers on web-application input handling, with observed weaknesses clustering around cross-site scripting and related injection-class flaws that are common to request-processing interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Best Practical Solutions over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0273MEDIUM Cross-site scripting (XSS) vulnerability in the web interface for Request Tracker (RT) 1.0 through 1.0.7 allows remote attackers to execute script via message bodies. | May 27, 2003 | 6.8 | 18 | NO | NO |
CVE-2012-2768MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the topic administration page in the RTFM extension 2.0.4 through 2.4.3 for Best Practical Solutions RT allow remote attacker | Aug 15, 2012 | 4.3 | 16 | NO | NO |
CVE-2006-2169MEDIUM RT: Request Tracker 3.5.HEAD allows remote attackers to obtain sensitive information via the Rows parameter in Dist/Display.html, which reveals the installation path in an error me | May 4, 2006 | 5.0 | 15 | NO | NO |
Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME enc | May 5, 2025 | 2.3 | 12 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Best Practical Solutions.
Media articles that mention a CVE ID that affects a product developed by Best Practical Solutions — matched by CVE ID, not by vendor name.