Rt

Vendor:

First CVE: Aug 6, 2008 · Active for 17 years

41
Total CVEs
More Total CVEs than 97% of tracked products
5.9
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
5.0
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Rt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2008
17 years ago
Most Recent CVE
May 28, 2025
422 days ago

CVE Severity & Scoring

Rt41 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (7.3%)
Unknown38 (92.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (7.3%)
High0 (0.0%)
Unknown38 (92.7%)
User Interaction
None0 (0.0%)
Unknown38 (92.7%)
Required3 (7.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (7.3%)
Unknown38 (92.7%)

Top CVEs

Signals from CVEs in this product scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote attackers to execute a
Jun 4, 20126.823NONO
Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allow remote authenticated users to ex
Apr 22, 20116.523NONO
Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versions before 4.0.8, allows remote attackers
Nov 11, 20126.822NONO
Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote attackers to hijack the authentication of
Jun 4, 20126.822NONO
Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges via unspecified vectors, a different vuln
Jun 4, 20127.521NONO
SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users to execute arbitrary SQL commands by lev
Jun 4, 20126.521NONO
Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the Mod
Aug 23, 20136.020NONO
Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated users to bypass intended access restricti
Jun 4, 20126.520NONO
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.
May 28, 20256.119NONO
Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.
May 28, 20256.119NONO

Exploit Exposure

Signals from CVEs in this product scope (41 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (41 CVEs).

Media Mentions

Signals from CVEs in this product scope (41 CVEs).

Top CNAs Publishing CVEs For Rt

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.2.215.02.4%00
4.2.115.02.4%00
4.2.015.02.4%00
4.0.984.61.7%00
4.0.8124.71.6%00
4.0.7124.71.7%00
4.0.6124.71.6%00
4.0.5204.91.7%00
4.0.4205.01.8%00
4.0.3214.81.7%00
4.0.2214.91.7%00
4.0.1294.71.7%00
4.0.1194.71.7%00
4.0.1094.71.7%00
4.0.1214.91.7%00
4.0.0275.01.8%00
3.8.9254.91.8%00
3.8.8274.91.8%00
3.8.7274.91.8%00
3.8.6274.81.8%00