OTRS AG maintains a ticket-request and IT service-management platform that, despite a narrow product line, operates as a critical communication hub in many enterprise and service-provider environments. The vendor's disclosures cluster around a modest portfolio comprising the core OTRS system, OTRS ITSM, Help Desk, and FAQ modules, and recur consistently through web-application input-handling weaknesses—particularly cross-site scripting and improper input validation—alongside exposure of sensitive configuration and system information. These weakness classes reflect the platform's role as a web-facing request aggregator that processes and stores customer and incident data, creating both an application-layer attack surface and a data-exposure risk. A moderate tendency toward public exploit availability characterizes this vendor's disclosures, reflecting the accessibility and appeal of ticketing systems to both researchers and adversaries. Defenders deploying OTRS should prioritize patches addressing input validation and XSS, inventory instances carefully, and restrict external access; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by OTRS AG over time
Of all the CVEs published by OTRS AG as a CNA, 86.6% affect products that OTRS AG develops as a vendor.
Of all the CVEs published that affect products developed by OTRS AG, 44.7% are self-published by OTRS AG as a CNA.
Signals from CVEs in this vendor scope (159 CVEs).
159 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16921HIGH In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manip | Dec 8, 2017 | 8.8 | 50 | NO | YES |
CVE-2026-48188CRITICAL An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication b | Jun 1, 2026 | 9.1 | 39 | NO | NO |
CVE-2022-4427CRITICAL Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice
This issue affects OTRS: from 7.0.1 bef | Dec 19, 2022 | 9.8 | 31 | NO | NO |
CVE-2005-3893HIGH Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL | Nov 29, 2005 | 7.5 | 31 | NO | YES |
CVE-2026-48209HIGH An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform reflected cross-site scripting | Jun 1, 2026 | 7.1 | 30 | NO | NO |
CVE-2016-5843CRITICAL Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to ex | Sep 17, 2016 | 9.4 | 30 | NO | NO |
CVE-2024-23790CRITICAL Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes.
This issue affects OTRS: from 7 | Jan 29, 2024 | 9.8 | 29 | NO | NO |
CVE-2026-48208MEDIUM An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email | Jun 1, 2026 | 6.5 | 28 | NO | NO |
CVE-2022-39051HIGH Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package | Sep 5, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-36100HIGH Specially crafted string in OTRS system configuration can allow the execution of any system command. | Mar 21, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (159 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by OTRS AG.
Media articles that mention a CVE ID that affects a product developed by OTRS AG — matched by CVE ID, not by vendor name.