Enhancesoft maintains a narrow but prominent product line centered on osTicket, a widely deployed open-source ticketing and help-desk platform, alongside related audit and logging tools. Vulnerabilities affecting the vendor concentrate in web-application input-handling and validation weaknesses, including cross-site scripting, SQL injection, and downstream injection flaws that are characteristic of server-side request processing in customer-facing applications. These disclosures skew toward moderate severity outcomes and frequently acquire public exploit code, reflecting both the accessibility of web applications and the attractiveness of help-desk systems as targets for credential harvesting and lateral-movement pivots. Defenders using osTicket should prioritize input-validation patches and treat exposed instances—particularly those internet-facing—as high-risk; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Enhancesoft over time
Signals from CVEs in this vendor scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22200HIGH Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attack | Jan 12, 2026 | 7.5 | 87 | NO | YES |
CVE-2020-24881CRITICAL SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. | Nov 2, 2020 | 9.8 | 86 | NO | YES |
CVE-2019-14750MEDIUM An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the f | Aug 7, 2019 | 6.1 | 48 | NO | YES |
CVE-2019-14749HIGH An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are gene | Aug 7, 2019 | 8.8 | 46 | NO | YES |
CVE-2019-11537MEDIUM In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .c | Apr 25, 2019 | 6.1 | 35 | NO | YES |
CVE-2021-45811MEDIUM A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywo | Sep 8, 2023 | 6.5 | 33 | NO | YES |
CVE-2018-7193MEDIUM Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" | Mar 27, 2018 | 6.1 | 33 | NO | YES |
CVE-2019-14748MEDIUM An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upl | Aug 7, 2019 | 5.4 | 32 | NO | YES |
CVE-2018-7196MEDIUM Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" param | Mar 27, 2018 | 6.1 | 32 | NO | YES |
CVE-2018-7192MEDIUM Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the " | Mar 27, 2018 | 6.1 | 32 | NO | YES |
Signals from CVEs in this vendor scope (47 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Enhancesoft.
Media articles that mention a CVE ID that affects a product developed by Enhancesoft — matched by CVE ID, not by vendor name.