Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zammad

First CVE: Mar 13, 2017Active for: 9 yearsTotal CVEs: 90
27.3
VTI Score
Low

Zammad is an open-source customer-support and ticketing platform that, despite a narrow product scope, occupies a prominent position among widely deployed help-desk and communication tools. Its vulnerability profile concentrates almost entirely in the core Zammad application and skews toward serious outcomes, with a meaningful share reaching critical severity. The recurring exposure reflects web-application fundamentals: cross-site scripting and input-handling weaknesses, authorization gaps, and access-control deficiencies that are characteristic of ticket-management systems handling user input and sensitive customer data. Defenders should prioritize tracking Zammad's security releases and apply patches promptly, particularly for internet-exposed instances; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
90
Total CVEs
More Total CVEs than 99% of tracked vendors
9.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zammad over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 13, 2017
9 years ago
Most Recent CVE
Apr 8, 2026
107 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (90 CVEs).

90 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-42090CRITICAL
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.
Oct 7, 20219.830NONO
CVE-2021-42094CRITICAL
An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.
Oct 7, 20219.830NONO
CVE-2017-6080CRITICAL
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP Access-Control headers. To explo
Mar 13, 20179.830NONO
CVE-2017-5619CRITICAL
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the v
Mar 13, 20179.830NONO
CVE-2022-35490CRITICAL
Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts,
Aug 8, 20229.829NONO
CVE-2021-42091CRITICAL
An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.
Oct 7, 20219.129NONO
CVE-2020-26030CRITICAL
An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a val
Dec 28, 20209.829NONO
CVE-2022-27332CRITICAL
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing
Apr 27, 20229.128NONO
CVE-2021-42086HIGH
An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.
Oct 7, 20218.828NONO
CVE-2026-34724HIGH
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RCE via AI Agent exists. Impact i
Apr 8, 20267.225NONO
View all 90 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products90 CVEs
67%
22%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.1%)
Network89 (98.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low88 (97.8%)
High2 (2.2%)
Unknown0 (0.0%)
User Interaction
None71 (78.9%)
Unknown0 (0.0%)
Required19 (21.1%)
Privileges Required
Low37 (41.1%)
High7 (7.8%)
None46 (51.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (90 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zammad.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zammad — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zammad's Products

View all 3 CNAs →

Top CWEs