Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bestpractical

First CVE: Aug 6, 2008Active for: 18 yearsTotal CVEs: 70
25.4
VTI Score
Low

Bestpractical develops Request Tracker (RT) and related incident-response and mobility extensions, a modestly scoped but prominently deployed suite of ticketing and workflow systems widely used in IT operations and security teams. The vendor's vulnerability exposure concentrates in a focused product line and recurs through web-application weakness classes, including cross-site scripting, cross-site request forgery, code injection, and sensitive information disclosure, reflecting the HTTP-facing and user-input processing demands inherent to web-based ticketing platforms. The severity profile leans toward moderate outcomes, consistent with the operational and data-handling context of ticketing systems rather than critical infrastructure or memory-unsafe components. Defenders should prioritize patches affecting the core RT product and its mobility and extension layers, as deployment in security and incident-response contexts amplifies the impact of authentication and injection flaws. Current exploitation status and severity distribution are shown alongside this summary.

FAUCET AI Generated
70
Total CVEs
More Total CVEs than 99% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.5
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bestpractical over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2008
17 years ago
Most Recent CVE
May 21, 2026
64 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (70 CVEs).

70 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-3525HIGH
SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE:
May 10, 20137.529NOYES
CVE-2022-25801CRITICAL
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.
Jul 14, 20229.127NONO
CVE-2022-25800CRITICAL
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.
Jul 14, 20229.127NONO
CVE-2026-6841MEDIUM
Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, resul
May 21, 20266.126NONO
CVE-2021-38562HIGH
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middl
Oct 18, 20217.525NONO
CVE-2018-18898HIGH
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address
Mar 21, 20197.524NONO
CVE-2011-4458MEDIUM
Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote attackers to execute a
Jun 4, 20126.823NONO
CVE-2011-1686MEDIUM
Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allow remote authenticated users to ex
Apr 22, 20116.523NONO
CVE-2023-41259HIGH
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST
Nov 3, 20237.522NONO
CVE-2017-5944HIGH
The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain priv
Jul 3, 20178.822NONO
View all 70 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products70 CVEs
9%
74%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (27.1%)
Unknown51 (72.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (24.3%)
High2 (2.9%)
Unknown51 (72.9%)
User Interaction
None9 (12.9%)
Unknown51 (72.9%)
Required9 (12.9%)
Privileges Required
Low1 (1.4%)
High1 (1.4%)
None17 (24.3%)
Unknown51 (72.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (70 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bestpractical.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bestpractical — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bestpractical's Products

View all 4 CNAs →

Top CWEs