Osticket
Vendor:
First CVE: May 3, 2005 · Active for 21 years
45
Total CVEs
More Total CVEs than 97% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Osticket over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 3, 2005
21 years ago
Most Recent CVE
Apr 2, 2026
113 days ago
CVE Severity & Scoring
Osticket45 CVEs
73%
20%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network35 (77.8%)
Unknown10 (22.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (75.6%)
High1 (2.2%)
Unknown10 (22.2%)
User Interaction
None9 (20.0%)
Unknown10 (22.2%)
Required26 (57.8%)
Privileges Required
Low11 (24.4%)
High4 (8.9%)
None20 (44.4%)
Unknown10 (22.2%)
Top CVEs
Signals from CVEs in this product scope (45 CVEs).
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22200HIGH Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attack | Jan 12, 2026 | 7.5 | 87 | NO | YES |
CVE-2020-24881CRITICAL SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. | Nov 2, 2020 | 9.8 | 86 | NO | YES |
CVE-2019-14750MEDIUM An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the f | Aug 7, 2019 | 6.1 | 48 | NO | YES |
CVE-2019-14749HIGH An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are gene | Aug 7, 2019 | 8.8 | 46 | NO | YES |
CVE-2019-11537MEDIUM In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .c | Apr 25, 2019 | 6.1 | 35 | NO | YES |
CVE-2021-45811MEDIUM A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywo | Sep 8, 2023 | 6.5 | 33 | NO | YES |
CVE-2018-7193MEDIUM Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" | Mar 27, 2018 | 6.1 | 33 | NO | YES |
CVE-2019-14748MEDIUM An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upl | Aug 7, 2019 | 5.4 | 32 | NO | YES |
CVE-2018-7196MEDIUM Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" param | Mar 27, 2018 | 6.1 | 32 | NO | YES |
CVE-2018-7192MEDIUM Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the " | Mar 27, 2018 | 6.1 | 32 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (45 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.2% of CVEs· 96th percentile
Nuclei
10 CVEs
22.2% of CVEs· 98th percentile
ExploitDB
7 CVEs
15.6% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (45 CVEs).
Media Mentions
Signals from CVEs in this product scope (45 CVEs).
Top CNAs Publishing CVEs For Osticket
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.9.0 | 1 | 4.3 | 1.9% | 0 | 0 |
| 1.8.4 | 1 | 4.3 | 1.9% | 0 | 0 |
| 1.8.3 | 1 | 4.3 | 1.9% | 0 | 0 |
| 1.8.1.2 | 1 | 4.3 | 1.9% | 0 | 0 |
| 1.8.1.1 | 1 | 4.3 | 1.9% | 0 | 0 |
| 1.8.1 | 1 | 4.3 | 1.9% | 0 | 0 |
| 1.8.0.4 | 1 | 4.3 | 1.9% | 0 | 0 |
| 1.8.0.3 | 1 | 4.3 | 1.9% | 0 | 0 |
| 1.8.0.2 | 1 | 4.3 | 1.9% | 0 | 0 |
| 1.8.0.1 | 1 | 4.3 | 1.9% | 0 | 0 |
| 1.8.0 | 1 | 4.3 | 1.9% | 0 | 0 |
| 1.6.0 | 1 | 4.3 | 1.9% | 0 | 0 |
| 1.6 | 5 | 5.5 | 2.5% | 0 | 2 |
| 1.3.0 | 4 | 5.5 | 1.9% | 0 | 1 |
| 1.2.7 | 4 | 5.5 | 1.9% | 0 | 1 |
| 1.17.2 | 3 | 5.7 | 0.6% | 0 | 0 |
| 1.14.2 | 1 | 5.4 | 0.5% | 0 | 0 |
| 1.10.1 | 1 | 6.1 | 1.1% | 0 | 0 |
| 1.0 | 1 | 4.3 | 1.9% | 0 | 0 |