Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

OTRS AG

First CVE: Nov 29, 2005Active for: 21 yearsTotal CVEs: 159
29.9
VTI Score
Low

OTRS AG maintains a ticket-request and IT service-management platform that, despite a narrow product line, operates as a critical communication hub in many enterprise and service-provider environments. The vendor's disclosures cluster around a modest portfolio comprising the core OTRS system, OTRS ITSM, Help Desk, and FAQ modules, and recur consistently through web-application input-handling weaknesses—particularly cross-site scripting and improper input validation—alongside exposure of sensitive configuration and system information. These weakness classes reflect the platform's role as a web-facing request aggregator that processes and stores customer and incident data, creating both an application-layer attack surface and a data-exposure risk. A moderate tendency toward public exploit availability characterizes this vendor's disclosures, reflecting the accessibility and appeal of ticketing systems to both researchers and adversaries. Defenders deploying OTRS should prioritize patches addressing input validation and XSS, inventory instances carefully, and restrict external access; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
159
Total CVEs
More Total CVEs than 100% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by OTRS AG over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 29, 2005
20 years ago
Most Recent CVE
Jun 1, 2026
53 days ago

Self-Reporting Analysis

Of all the CVEs published by OTRS AG as a CNA, 86.6% affect products that OTRS AG develops as a vendor.

86.6%
13.4%
Self-reported: 71 (86.6%)
Third-party: 11 (13.4%)

Of all the CVEs published that affect products developed by OTRS AG, 44.7% are self-published by OTRS AG as a CNA.

44.7%
55.3%
Self-published: 71 (44.7%)
Other CNAs: 88 (55.3%)

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (159 CVEs).

159 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-16921HIGH
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manip
Dec 8, 20178.850NOYES
CVE-2026-48188CRITICAL
An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication b
Jun 1, 20269.139NONO
CVE-2022-4427CRITICAL
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This issue affects OTRS: from 7.0.1 bef
Dec 19, 20229.831NONO
CVE-2005-3893HIGH
Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL
Nov 29, 20057.531NOYES
CVE-2026-48209HIGH
An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform reflected cross-site scripting
Jun 1, 20267.130NONO
CVE-2016-5843CRITICAL
Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to ex
Sep 17, 20169.430NONO
CVE-2024-23790CRITICAL
Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7
Jan 29, 20249.829NONO
CVE-2026-48208MEDIUM
An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email
Jun 1, 20266.528NONO
CVE-2022-39051HIGH
Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package
Sep 5, 20228.828NONO
CVE-2021-36100HIGH
Specially crafted string in OTRS system configuration can allow the execution of any system command.
Mar 21, 20228.828NONO
View all 159 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products159 CVEs
72%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (0.6%)
Network112 (70.4%)
Unknown46 (28.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low111 (69.8%)
High2 (1.3%)
Unknown46 (28.9%)
User Interaction
None70 (44.0%)
Unknown46 (28.9%)
Required43 (27.0%)
Privileges Required
Low59 (37.1%)
High13 (8.2%)
None41 (25.8%)
Unknown46 (28.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (159 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
5.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by OTRS AG.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by OTRS AG — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For OTRS AG's Products

View all 5 CNAs →

Top CWEs