Bestpractical develops Request Tracker (RT) and related incident-response and mobility extensions, a modestly scoped but prominently deployed suite of ticketing and workflow systems widely used in IT operations and security teams. The vendor's vulnerability exposure concentrates in a focused product line and recurs through web-application weakness classes, including cross-site scripting, cross-site request forgery, code injection, and sensitive information disclosure, reflecting the HTTP-facing and user-input processing demands inherent to web-based ticketing platforms. The severity profile leans toward moderate outcomes, consistent with the operational and data-handling context of ticketing systems rather than critical infrastructure or memory-unsafe components. Defenders should prioritize patches affecting the core RT product and its mobility and extension layers, as deployment in security and incident-response contexts amplifies the impact of authentication and injection flaws. Current exploitation status and severity distribution are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bestpractical over time
Signals from CVEs in this vendor scope (70 CVEs).
70 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-3525HIGH SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE: | May 10, 2013 | 7.5 | 29 | NO | YES |
CVE-2022-25801CRITICAL Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools. | Jul 14, 2022 | 9.1 | 27 | NO | NO |
CVE-2022-25800CRITICAL Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool. | Jul 14, 2022 | 9.1 | 27 | NO | NO |
CVE-2026-6841MEDIUM Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, resul | May 21, 2026 | 6.1 | 26 | NO | NO |
CVE-2021-38562HIGH Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middl | Oct 18, 2021 | 7.5 | 25 | NO | NO |
CVE-2018-18898HIGH The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address | Mar 21, 2019 | 7.5 | 24 | NO | NO |
CVE-2011-4458MEDIUM Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote attackers to execute a | Jun 4, 2012 | 6.8 | 23 | NO | NO |
CVE-2011-1686MEDIUM Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allow remote authenticated users to ex | Apr 22, 2011 | 6.5 | 23 | NO | NO |
CVE-2023-41259HIGH Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST | Nov 3, 2023 | 7.5 | 22 | NO | NO |
CVE-2017-5944HIGH The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain priv | Jul 3, 2017 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (70 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bestpractical.
Media articles that mention a CVE ID that affects a product developed by Bestpractical — matched by CVE ID, not by vendor name.