Znuny is a help-desk and IT service-management platform whose vulnerability profile centers on its single core product and skews toward critical-severity outcomes. The recurring exposure involves application-layer input-handling and authorization weaknesses—code injection, cross-site scripting, eval injection, SQL injection, and improper access control—that are characteristic of web-facing ticketing systems and reflect parser and query-building complexity in such platforms. Defenders should treat this vendor's advisories as a patching priority for internet-reachable instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Znuny over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-26846CRITICAL An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata. | May 12, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-50592MEDIUM In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in
AdminCommunicationLog (aka the communication log administration view). | Jun 5, 2026 | 6.4 | 28 | NO | NO |
CVE-2025-26845CRITICAL An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the | May 8, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-26844CRITICAL An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag. | May 8, 2025 | 9.8 | 28 | NO | NO |
CVE-2024-32491CRITICAL An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file (via a manipulated AJAX Request) to an a | Apr 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2026-50591MEDIUM In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences. | Jun 5, 2026 | 5.4 | 26 | NO | NO |
CVE-2025-26847HIGH An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked. | May 8, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-26842HIGH An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to users with access to the Communica | May 8, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-32493HIGH An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX requ | Apr 29, 2024 | 8.8 | 22 | NO | NO |
CVE-2024-48938HIGH Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied from Microsoft Word could lead to | Oct 11, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Znuny.
Media articles that mention a CVE ID that affects a product developed by Znuny — matched by CVE ID, not by vendor name.