Osticket is a modestly represented open-source help-desk and ticketing platform that, despite a narrow product footprint, maintains significant visibility in the vulnerability landscape owing to its widespread adoption across small-to-medium organizations and service providers. Vulnerabilities affecting the vendor skew toward application-layer input and file-handling flaws, with a notable share reaching critical severity and a pronounced tendency to acquire public exploit code. The exposure recurs across the core Osticket product and its support ticketing suite through weakness classes including cross-site scripting, SQL injection, unrestricted file upload, and path traversal—classic web-application vectors that reflect the product's role as a user-facing, internet-accessible service. Defenders should prioritize patching this vendor's releases given the exploitation readiness of its disclosed flaws and the direct exposure of ticketing systems to both authenticated and unauthenticated attack surfaces. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Osticket over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15580CRITICAL osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any ty | Oct 23, 2017 | 9.8 | 50 | NO | YES |
CVE-2017-14396CRITICAL In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to fil | Sep 12, 2017 | 9.8 | 41 | NO | YES |
CVE-2004-0613HIGH osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments director | Dec 6, 2004 | 7.5 | 32 | NO | YES |
CVE-2010-0605HIGH SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the i | Feb 11, 2010 | 7.5 | 31 | NO | YES |
CVE-2005-2154HIGH PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local f | Jul 6, 2005 | 7.5 | 28 | NO | YES |
CVE-2006-6733MEDIUM Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web script or HTML via the e parameter. | Dec 26, 2006 | 4.3 | 21 | NO | YES |
CVE-2017-15362MEDIUM osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link, aka XSS. Session ID and data theft may f | Oct 16, 2017 | 6.1 | 20 | NO | NO |
CVE-2005-2153HIGH SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable. | Jul 6, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-1437HIGH Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admin.php or (2) cat parameter to view.php. | May 3, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-1438HIGH PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter. | May 3, 2005 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Osticket.
Media articles that mention a CVE ID that affects a product developed by Osticket — matched by CVE ID, not by vendor name.