Zammad is an open-source customer-support and ticketing platform that, despite a narrow product scope, occupies a prominent position among widely deployed help-desk and communication tools. Its vulnerability profile concentrates almost entirely in the core Zammad application and skews toward serious outcomes, with a meaningful share reaching critical severity. The recurring exposure reflects web-application fundamentals: cross-site scripting and input-handling weaknesses, authorization gaps, and access-control deficiencies that are characteristic of ticket-management systems handling user input and sensitive customer data. Defenders should prioritize tracking Zammad's security releases and apply patches promptly, particularly for internet-exposed instances; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zammad over time
Signals from CVEs in this vendor scope (90 CVEs).
90 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42090CRITICAL An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled. | Oct 7, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-42094CRITICAL An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages. | Oct 7, 2021 | 9.8 | 30 | NO | NO |
CVE-2017-6080CRITICAL An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP Access-Control headers. To explo | Mar 13, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-5619CRITICAL An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the v | Mar 13, 2017 | 9.8 | 30 | NO | NO |
CVE-2022-35490CRITICAL Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, | Aug 8, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-42091CRITICAL An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration. | Oct 7, 2021 | 9.1 | 29 | NO | NO |
CVE-2020-26030CRITICAL An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a val | Dec 28, 2020 | 9.8 | 29 | NO | NO |
CVE-2022-27332CRITICAL An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing | Apr 27, 2022 | 9.1 | 28 | NO | NO |
CVE-2021-42086HIGH An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request. | Oct 7, 2021 | 8.8 | 28 | NO | NO |
CVE-2026-34724HIGH Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RCE via AI Agent exists. Impact i | Apr 8, 2026 | 7.2 | 25 | NO | NO |
Signals from CVEs in this vendor scope (90 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zammad.
Media articles that mention a CVE ID that affects a product developed by Zammad — matched by CVE ID, not by vendor name.